Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
affected
Any version before 25.3
affected
Default status
affected
Any version before 25.3
affected
Default status
affected
Any version before 25.3
affected
Description
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
Problem types
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
Product status
Any version before 25.3
Any version before 25.3
Any version before 25.3
Credits
SAFA Team
References
www.gendigital.com/us/en/contact-us/security-advisories/