HIGH
Avast and AVG Antivirus for Windows vulnerable to Privilege Escalation
Published Dec 5, 2022
8.8
HIGHCVSS 3.1
EPSS 0.73%
Description
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.
Affected products
-
- Version 20.5StatusaffectedConstraints<=22.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NortonLifeLock | Avast and AVG Antivirus | unaffected |
|
OR
- ≥ 20.5 · ≤ 22.9
- ≥ 20.5 · ≤ 22.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51534 Advisory
- https://support.norton.com/sp/static/external/tools/security-advisories.html Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51534 | Advisory | |
| https://support.norton.com/sp/static/external/tools/security-advisories.html | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NLOK
Published Dec 5, 2022
Updated Apr 14, 2025
Reserved Nov 29, 2022
Link CVE-2022-4173
CISA Vulnrichment
Updated Apr 14, 2025
ENISA EUVD
EUVD-2022-51534 Assigner NLOK
Published Dec 5, 2022
Updated Apr 14, 2025
Exploited since n/a
Link EUVD-2022-51534