The specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
. Was ZDI-CAN-22803.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48840 | AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. . Was ZDI-CAN-22803. |
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1006/ |
|
Thu, 19 Dec 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avg
Avg antivirus |
|
| CPEs | cpe:2.3:a:avg:antivirus:23.11.8635.809:*:*:*:free:*:*:* | |
| Vendors & Products |
Avg
Avg antivirus |
|
| Metrics |
cvssV3_1
|
Sat, 23 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. . Was ZDI-CAN-22803. | |
| Title | AVG AntiVirus Free Link Following Denial-of-Service Vulnerability | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-11-23T01:26:24.972Z
Reserved: 2024-07-29T20:26:32.437Z
Link: CVE-2024-7235
Updated: 2024-11-23T01:17:38.633Z
Status : Analyzed
Published: 2024-11-22T22:15:16.307
Modified: 2024-12-19T19:42:37.133
Link: CVE-2024-7235
No data.
OpenCVE Enrichment
No data.
EUVD