CVE-2014-2956: Critical severity avg safeguard vulnerability
ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2956?
CVE-2014-2956 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2014-2956?
To fix CVE-2014-2956, update AVG Secure Search toolbar to version 18.1.7.598 or later and AVG Safeguard to 18.1.7.644 or later.
What types of software are affected by CVE-2014-2956?
CVE-2014-2956 affects AVG Secure Search toolbar versions prior to 18.1.7.598 and AVG Safeguard versions prior to 18.1.7.644.
What is the impact of CVE-2014-2956 on affected systems?
CVE-2014-2956 allows remote attackers to execute arbitrary code, potentially compromising affected systems.
Are there any known exploits for CVE-2014-2956?
Yes, there are known exploits that leverage CVE-2014-2956 to execute arbitrary code remotely.