Arbitrary File Deletion Vulnerability in Avast Antivirus
CVE-2020-10861

7.5HIGH

Key Information:

Vendor

Avast

Status
Vendor
CVE Published:
1 April 2020

What is CVE-2020-10861?

A security flaw in Avast Antivirus prior to version 20 enables attackers to exploit the aswTask RPC endpoint in the Avast Service (AvastSvc.exe). Through this vulnerability, an attacker can perform arbitrary file deletion from the Avast program path when the Self Defense feature is enabled. This poses a serious risk as malicious actors can potentially erase critical files related to the antivirus's functionality, undermining its effectiveness and compromising system security.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.