vendor:
AVG Anti-Spyware
by:
Idan Malihi
6.8
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: AVG Anti-Spyware
Affected Version From: 7.5
Affected Version To: 7.5
Patch Exists: NO
Related CWE: CVE-2023-36167
CPE: a:avg:anti_spyware:7.5
Platforms Tested: Windows
2023
AVG Anti Spyware 7.5 – Unquoted Service Path
The AVG Anti-Spyware 7.5 software on Windows 10 Pro has an unquoted service path vulnerability, which allows local users to gain privileges via a crafted executable file in the %SYSTEMDRIVE% folder.
Mitigation:
To mitigate this vulnerability, the vendor should update the software to include the correct quoting of the service path. Users should also ensure that their systems have the latest security updates installed.