CVE-2015-8620: Buffer Overflow
Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8620?
CVE-2015-8620 is rated as a high severity vulnerability due to its ability to allow local users to gain elevated privileges.
How do I fix CVE-2015-8620?
To fix CVE-2015-8620, users should update their Avast software to version 11.1.2253 or later.
Which Avast products are affected by CVE-2015-8620?
CVE-2015-8620 affects Avast Free Antivirus, Internet Security, Pro Antivirus, and Premier versions up to 11.1.2245.
How does CVE-2015-8620 exploit the system?
CVE-2015-8620 exploits a heap-based buffer overflow vulnerability by sending a specially crafted Unicode file path in an IOCTL request.
Can CVE-2015-8620 be exploited remotely?
No, CVE-2015-8620 is a local privilege escalation vulnerability and requires local access to the system to exploit.