Local Denial of Service Vulnerability in AVG AntiVirus Free
CVE-2024-7236

5.5MEDIUM

Key Information:

Vendor

Avg

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-7236?

The AVG AntiVirus Free software exhibits a vulnerability in its installer that allows local attackers to cause a denial-of-service condition. By exploiting this flaw through the creation of symbolic links, an attacker can manipulate the update mechanism to generate files at arbitrary locations. This exploitation requires the attacker to have low-privileged code execution capabilities on the target machine, leading to persistent disruptions and unavailability of the antivirus service.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.