vendor:
Premium Security Suite
by:
Unknown
7,2
CVSS
HIGH
Race Condition
362
CWE
Product Name: Premium Security Suite
Affected Version From: Avira Premium Security Suite, up to date version 10.0.0.565.
Affected Version To: Avira Premium Security Suite, up to date version 10.0.0.565.
Patch Exists: Yes
Related CWE: Unknown
CPE: avira:premium_security_suite
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
Unknown
Avira Premium Security Suite Race Condition Vulnerability
The avipbb.sys kernel driver distributed with Avira Premium Security Suite contains a race condition vulnerability in the handling paramaters of NtCreatekey function. Exploitation of this issue allows an attacker to crash system(make infamous BSoD) or gain escalated priviliges. An attacker would need local access to a vulnerable computer to exploit this vulnerability.
Mitigation:
The vendor has released a patch to address this vulnerability.