Avast

Antivirus

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.46%
  • Veröffentlicht 01.04.2020 17:15:16
  • Zuletzt bearbeitet 21.11.2024 04:56:14

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a reboot via RPC from a Low Integrity process.

Exploit
  • EPSS 0.64%
  • Veröffentlicht 01.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 04:56:14

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 01.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 04:56:14

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Local Privilege Escalation (LPE) via RPC.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 01.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 04:56:14

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avast Program Path via RPC, when Self Defense is Enable...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 01.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 04:56:14

An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Denial of Service of the Avast Service (AvastSvc.exe).

Exploit
  • EPSS 0.3%
  • Veröffentlicht 01.11.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:27

A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 23.10.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:31:40

An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass s...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 18.07.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:46

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is ...

Exploit
  • EPSS 0.99%
  • Veröffentlicht 27.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary files. This vulnerability is exploitable by any unprivileged user whe...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 27.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product, opening a door to subsequent ...