Vulnerability Name: | CVE-2020-10867 (CCN-178950) | ||||||||||||
Assigned: | 2020-04-01 | ||||||||||||
Published: | 2020-04-01 | ||||||||||||
Updated: | 2020-04-02 | ||||||||||||
Summary: | An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-668 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-10867 Source: XF Type: UNKNOWN avast-cve202010867-sec-bypass(178950) Source: MISC Type: Release Notes, Vendor Advisory https://forum.avast.com/index.php?topic=232420.0 Source: MISC Type: Release Notes, Vendor Advisory https://forum.avast.com/index.php?topic=232423.0 Source: CCN Type: Avast GIT Repository Multiple Vulnerability Disclosure in Avast AntiVirus (RPC Service) Source: MISC Type: Exploit, Third Party Advisory https://github.com/umarfarook882/Avast_Multiple_Vulnerability_Disclosure/blob/master/README.md Source: CCN Type: Avast Web site Avast Antivirus | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |