header-logo
Suggest Exploit
vendor:
Avira Internet Security Suite
by:
Ahmad Moghimi
8,8
CVSS
HIGH
Filter Bypass and Privilege Escalation
264
CWE
Product Name: Avira Internet Security Suite
Affected Version From: Latest
Affected Version To: Latest
Patch Exists: YES
Related CWE: NO-CVE
CPE: a:avira:avira_internet_security_suite
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XPSP3
2013

Avira internet security avipbb.sys filter bypass and privilege escalation – 0Day

Ahmad Moghimi discovered a filter bypass and privilege escalation vulnerability in Avira internet security avipbb.sys. This vulnerability allows an attacker to bypass the filter and gain elevated privileges. The vulnerability affects the latest version of Avira internet security. The exploit code is available in the form of a .7z file and a demo is available in the form of a .swf file.

Mitigation:

Users should update to the latest version of Avira internet security to mitigate this vulnerability.
Source

Exploit-DB raw data:

# Exploit Title: Avira internet security avipbb.sys filter bypass and
privilege escalation - 0Day
# Date: 2013-10-17
# Exploit Author: Ahmad Moghimi (http://mallocat.com
<http://mallocat.com/>, https://twitter.com/mall0cat)
# Vendor Homepage: http://www.avira.com/
# Software Link:
http://premium.avira-update.com/package/webloader/win32/iss/avira_internet_security_suite.exe
# Version: Latest
# Tested on: Windows XPSP3
# CVE : NO-CVE

Reference : http://mallocat.com/another-journey-to-antivirus-escalation/
Demo: http://mallocat.com/wp-content/uploads/2013/10/avira0.swf
Exploit code:
http://mallocat.com/wp-content/uploads/2013/10/AviraAvipbbExploit.7z
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/29125.7z