The specific flaw exists within the AVG Installer. By creating a symbolic link, an attacker can abuse the update functionality to create a file. An attacker can leverage this vulnerability to create a persistent denial-of-service condition on the system. Was ZDI-CAN-22942.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48841 | AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AVG Installer. By creating a symbolic link, an attacker can abuse the update functionality to create a file. An attacker can leverage this vulnerability to create a persistent denial-of-service condition on the system. Was ZDI-CAN-22942. |
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1009/ |
|
Thu, 19 Dec 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avg
Avg antivirus |
|
| CPEs | cpe:2.3:a:avg:antivirus:23.12.8700.812:-:*:*:free:*:*:* | |
| Vendors & Products |
Avg
Avg antivirus |
|
| Metrics |
cvssV3_1
|
Sat, 23 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AVG Installer. By creating a symbolic link, an attacker can abuse the update functionality to create a file. An attacker can leverage this vulnerability to create a persistent denial-of-service condition on the system. Was ZDI-CAN-22942. | |
| Title | AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-11-23T01:26:25.130Z
Reserved: 2024-07-29T20:26:49.635Z
Link: CVE-2024-7236
Updated: 2024-11-23T01:17:44.404Z
Status : Analyzed
Published: 2024-11-22T22:15:16.427
Modified: 2024-12-19T19:35:22.970
Link: CVE-2024-7236
No data.
OpenCVE Enrichment
No data.
EUVD