AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability
CVE-2024-7237
7.8HIGH
What is CVE-2024-7237?
A local privilege escalation vulnerability is present in AVG AntiVirus Free through a flaw in the AVG Service. Attackers with low-privileged access can create a symbolic link, allowing them to manipulate files and directories the service interacts with. By exploiting this flaw, it's possible for an attacker to elevate their privileges and execute arbitrary code with SYSTEM-level access, which could lead to significant compromises of the affected system's security.
Affected Version(s)
AntiVirus Free 23.12.8700.813