CVE-2022-4173

A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:avast:avast:*:*:*:*:*:*:*:*
cpe:2.3:a:avast:avg_antivirus:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:57

Type Values Removed Values Added
Summary A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10. A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.

07 Dec 2022, 15:41

Type Values Removed Values Added
CWE CWE-269
First Time Avast avg Antivirus
Avast
Avast avast
References (MISC) https://support.norton.com/sp/static/external/tools/security-advisories.html - (MISC) https://support.norton.com/sp/static/external/tools/security-advisories.html - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:avast:avast:*:*:*:*:*:*:*:*
cpe:2.3:a:avast:avg_antivirus:*:*:*:*:*:*:*:*

06 Dec 2022, 00:18

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-06 00:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-4173

Mitre link : CVE-2022-4173

CVE.ORG link : CVE-2022-4173


JSON object : View

Products Affected

avast

  • avg_antivirus
  • avast
CWE
CWE-269

Improper Privilege Management