VYPR
Vendor

Avast\!

Products
48
CVEs
104
Across products
166
Status
Private

Products

48
View all 48 products →

Recent CVEs

104
View all 104 CVEs →
  • CVE-2025-13032CriNov 11, 2025
    risk 0.64cvss 9.9epss 0.00

    Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

  • CVE-2020-10867CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.

  • CVE-2017-8307CriApr 27, 2017
    risk 0.64cvss 9.8epss 0.02

    In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary files. This vulnerability is exploitable by any unprivileged user when Avast Self-Defense is…

  • CVE-2025-3500CriDec 1, 2025
    risk 0.59cvss 9.0epss 0.00

    Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

  • CVE-2021-45337HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing" process wsc_proxy.exe which could lead to acquire antimalware (AM-PPL) protection.

  • CVE-2021-45336HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed code to gain elevated privileges by using system IPC interfaces which could lead to exit the sandbox and acquire SYSTEM privileges.

  • CVE-2021-45335HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.00

    Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.

  • CVE-2016-3986HigApr 12, 2016
    risk 0.54cvss 7.8epss 0.08

    Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing.

  • CVE-2023-5760HigNov 8, 2023
    risk 0.53cvss 8.2epss 0.00

    A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue…

  • CVE-2025-71326HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious…

  • CVE-2022-26522HigMay 8, 2026
    risk 0.51cvss 7.8epss 0.00

    The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at…

  • CVE-2020-37037HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with…

  • CVE-2025-10101HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast…

  • CVE-2024-13961HigMay 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and…

  • CVE-2024-7233HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2024-7232HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2024-7231HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-7230HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-7229HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-7227HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on…