Arbitrary Memory Address Overwrite in Avast Antivirus by Avast
CVE-2020-10860

7.5HIGH

Key Information:

Vendor

Avast

Status
Vendor
CVE Published:
1 April 2020

What is CVE-2020-10860?

An arbitrary memory address overwrite vulnerability exists within the aswAvLog Log Library in Avast Antivirus prior to version 20. This flaw can lead to a Denial of Service condition for the Avast service (AvastSvc.exe), impacting system security and availability. Attackers may exploit this vulnerability to disrupt the normal functioning of the antivirus, hindering its ability to protect users from potential threats.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.