Code Injection Vulnerability in Avast Antivirus Products
CVE-2017-5567

6.7MEDIUM

Key Information:

Vendor

Avast

Vendor
CVE Published:
21 March 2017

What is CVE-2017-5567?

The vulnerability allows local attackers to exploit a code injection flaw within multiple Avast antivirus products. By bypassing self-protection mechanisms, these attackers can inject arbitrary code under the guise of a 'DoubleAgent' attack. This exploitation leverages the fact that these products do not implement Protected Processes, enabling attackers to manipulate registry settings and gain control over Avast processes. By temporarily renaming registry keys, adversaries can effectively compromise the integrity of the security software.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.