vendor:
Avast Antivirus
by:
Google Security Research
7,8
CVSS
HIGH
Authenticode Parsing
119
CWE
Product Name: Avast Antivirus
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
Avast Memory Corruption Vulnerability
This vulnerability is related to the parsing of Authenticode in Avast. The attached PE file causes memory corruption in Avast. The memory corruption occurs when the address of the parameter is set to 0x30303030. This leads to an access violation and the execution of malicious code.
Mitigation:
The user should update to the latest version of Avast to ensure that the vulnerability is patched.