First published: Thu Jul 27 2017(Updated: )
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avira Avira Antivirus for Small Business | <=8.3.36.59 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10402 is considered critical because it allows remote code execution as NT AUTHORITY\SYSTEM.
To fix CVE-2016-10402, upgrade to Avira Antivirus version 8.3.36.60 or later.
CVE-2016-10402 affects Avira Antivirus versions prior to 8.3.36.60.
CVE-2016-10402 is a remote code execution vulnerability caused by an integer overflow and heap-based buffer underflow.
CVE-2016-10402 can be exploited by an attacker who sends a specially crafted PE file to the vulnerable system.