The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-22806.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48833 | Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-22806. |
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-999/ |
|
Mon, 09 Dec 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avast
Avast free Antivirus |
|
| CPEs | cpe:2.3:a:avast:free_antivirus:23.11.6090:build_23.11.8365.809:*:*:*:*:*:* | |
| Vendors & Products |
Avast
Avast free Antivirus |
|
| Metrics |
cvssV3_1
|
Sat, 23 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-22806. | |
| Title | Avast Free Antivirus Link Following Denial-of-Service Vulnerability | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-11-23T01:26:25.282Z
Reserved: 2024-07-29T20:22:57.091Z
Link: CVE-2024-7228
Updated: 2024-11-23T01:17:50.044Z
Status : Analyzed
Published: 2024-11-22T22:15:15.417
Modified: 2024-12-09T20:08:59.000
Link: CVE-2024-7228
No data.
OpenCVE Enrichment
No data.
EUVD