First published: Wed Apr 13 2016(Updated: )
Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Antivirus | <=11.1.2245 | |
Avast Internet Security | <=11.1.2245 | |
Avast Antivirus | <=11.1.2245 | |
Avast Antivirus | <=11.1.2245 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8620 is rated as a high severity vulnerability due to its ability to allow local users to gain elevated privileges.
To fix CVE-2015-8620, users should update their Avast software to version 11.1.2253 or later.
CVE-2015-8620 affects Avast Free Antivirus, Internet Security, Pro Antivirus, and Premier versions up to 11.1.2245.
CVE-2015-8620 exploits a heap-based buffer overflow vulnerability by sending a specially crafted Unicode file path in an IOCTL request.
No, CVE-2015-8620 is a local privilege escalation vulnerability and requires local access to the system to exploit.