Time-of-Check/Time-of-Use Vulnerability in Avast and AVG Antivirus for Windows
CVE-2023-1585

6.5MEDIUM

Key Information:

Vendor

Avast

Vendor
CVE Published:
19 April 2023

What is CVE-2023-1585?

A Time-of-Check/Time-of-Use (TOCTOU) vulnerability was identified in the Quarantine process of Avast and AVG Antivirus for Windows. This security flaw allows an attacker to exploit the timing window between checking a file's status and using it, leading to the potential for arbitrary file or directory deletion. Users are advised to upgrade to Avast and AVG Antivirus version 22.11 or later, and ensure their virus definitions are updated from 14 February 2023 onward to mitigate risks associated with this vulnerability.

Affected Version(s)

Avast Antivirus Windows 22.5 <= 22.10

AVG Antivirus Windows 22.5 <= 22.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.