CVE-2014-9632: High severity AVG Protection vulnerability
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9632?
CVE-2014-9632 is classified as a privilege escalation vulnerability.
How do I fix CVE-2014-9632?
To fix CVE-2014-9632, update AVG Internet Security to version 2013.3495 Hot Fix 18 or later, and AVG Protection to version 2015.5315 or later.
What systems are affected by CVE-2014-9632?
CVE-2014-9632 affects AVG Internet Security versions prior to 2013.3495 and 2015.x up to 2015.5314, as well as AVG Protection versions prior to 2015.5315.
What type of attack does CVE-2014-9632 enable?
CVE-2014-9632 allows local users to write to arbitrary memory locations, enabling privilege escalation attacks.
Who can exploit CVE-2014-9632?
Local users with access to a vulnerable version of AVG Internet Security or AVG Protection can exploit CVE-2014-9632.