First published: Thu Jul 18 2019(Updated: )
In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast AntiVirus | <19.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11230 is a vulnerability in Avast Antivirus before version 19.4 that allows a local administrator to trick the product into renaming arbitrary files.
A local administrator can exploit CVE-2019-11230 by replacing the Logs\Update.log file with a symlink, causing the product to rename the target of the symlink the next time it attempts to write to the log file.
CVE-2019-11230 has a severity rating of medium with a CVSS score of 4.4.
Avast Antivirus before version 19.4 is affected by CVE-2019-11230.
To fix CVE-2019-11230, update to Avast Antivirus version 19.4 or later.