Untrusted Search Path Vulnerability in Avast Free Antivirus by Avast
CVE-2010-3126

Currently unrated

Key Information:

Vendor

Avast

Vendor
CVE Published:
26 August 2010

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2010-3126?

This vulnerability allows local users and potentially remote attackers to execute arbitrary code on affected systems through a malicious mfc90loc.dll file. The exploit occurs when this DLL is placed in the same directory as an Avast license file, leading to unauthorized access and potential system compromises. Users are advised to update their Avast Free Antivirus to mitigate this risk.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.