Arbitrary Modification Vulnerability in Avast Antivirus
CVE-2020-10865

7.5HIGH

Key Information:

Vendor

Avast

Status
Vendor
CVE Published:
1 April 2020

What is CVE-2020-10865?

A vulnerability in Avast Antivirus prior to version 20 enables attackers to exploit the aswTask RPC endpoint within the TaskEx library of the Avast Service (AvastSvc.exe). This exploitation allows for unauthorized modifications to the Components section of the Stats.ini file, potentially compromising the application's integrity and functionality when initiated from a Low Integrity process.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.