Vulnerability Name: | CVE-2020-10866 (CCN-178949) | ||||||||||||
Assigned: | 2020-04-01 | ||||||||||||
Published: | 2020-04-01 | ||||||||||||
Updated: | 2020-04-02 | ||||||||||||
Summary: | An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-326 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-10866 Source: XF Type: UNKNOWN avast-cve202010866-info-disc(178949) Source: MISC Type: Release Notes, Vendor Advisory https://forum.avast.com/index.php?topic=232420.0 Source: MISC Type: Release Notes, Vendor Advisory https://forum.avast.com/index.php?topic=232423.0 Source: CCN Type: Avast GIT Repository Multiple Vulnerability Disclosure in Avast AntiVirus (RPC Service) Source: MISC Type: Exploit, Third Party Advisory https://github.com/umarfarook882/Avast_Multiple_Vulnerability_Disclosure/blob/master/README.md Source: CCN Type: Avast Web site Avast Antivirus | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |