Code Injection Vulnerability in Avast Antivirus Products
CVE-2017-5567
6.7MEDIUM
What is CVE-2017-5567?
The vulnerability allows local attackers to exploit a code injection flaw within multiple Avast antivirus products. By bypassing self-protection mechanisms, these attackers can inject arbitrary code under the guise of a 'DoubleAgent' attack. This exploitation leverages the fact that these products do not implement Protected Processes, enabling attackers to manipulate registry settings and gain control over Avast processes. By temporarily renaming registry keys, adversaries can effectively compromise the integrity of the security software.