DLL Preloading Vulnerability in Avast and AVG Antivirus Products
CVE-2019-17093
7.8HIGH
What is CVE-2019-17093?
An issue identified in Avast and AVG antivirus products introduces a DLL preloading vulnerability that can potentially allow attackers to inject malicious code into systems. Specifically, the vulnerability allows the planting of the wbemcomn.dll file in the %WINDIR%\system32\ directory, which is then loaded into a protected-light process (PPL). This action may circumvent certain self-defense mechanisms of the antivirus software. The issue impacts components reliant on Windows Management Instrumentation (WMI), such as AVGSvc.exe and TuneupSmartScan.dll, particularly in versions prior to 19.8.