Code Injection Vulnerability in Avira Free Antivirus
CVE-2020-8961
9.8CRITICAL
What is CVE-2020-8961?
A vulnerability exists in Avira Free Antivirus prior to version 15.0.2004.1825 that allows external processes to circumvent the Self-Protection feature. This flaw enables code injection, leading to unauthorized write operations that could disable crucial security measures. By exploiting this vulnerability, an attacker can alter files at specified locations by crafting specific events and transferring them to the driver, thereby compromising the anti-virus functionality and overall system security.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved