vendor:
Avira Antivirus
by:
R-73eN
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: Avira Antivirus
Affected Version From: 15.0.21.86
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows 7
2016
Avira Antivirus >= 15.0.21.86 Command Execution (SYSTEM)
When the Avira Launcher manual update imports a zip file doesn't checks for " ../ " characters which makes it possible to do a path traversal and write anywhere in the system.
Mitigation:
Vendor released updated version which fix the vulnerability.