Privilege Escalation Vulnerability in AVG Internet Security
CVE-2014-9632

Currently unrated

Key Information:

Vendor

Avg

Vendor
CVE Published:
6 February 2015

What is CVE-2014-9632?

The TDI driver (avgtdix.sys) in AVG Internet Security versions prior to 2013.3495 Hot Fix 18 and 2015.x versions before 2015.5315 has a serious vulnerability that allows local users to manipulate memory. By sending a specifically crafted IOCTL call (0x830020f8), attackers can write to arbitrary memory locations, potentially enabling them to escalate their privileges and perform unauthorized actions within the system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2014-9632 : Privilege Escalation Vulnerability in AVG Internet Security