CVE-2019-17093: High severity avast antivirus vulnerability
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that use WMI, e.g., AVGSvc.exe 19.6.4546.0 and TuneupSmartScan.dll 19.1.884.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-17093.
What is the severity of CVE-2019-17093?
The severity of CVE-2019-17093 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2019-17093?
Avast antivirus versions before 19.8 and AVG antivirus versions before 19.8 are affected by CVE-2019-17093.
What is the impact of CVE-2019-17093?
CVE-2019-17093 allows an attacker to implant a malicious DLL into a protected-light process, potentially bypassing some self-defense mechanisms.
Are there any known fixes or mitigations for CVE-2019-17093?
Update Avast antivirus and AVG antivirus to version 19.8 or higher to mitigate the DLL Preloading vulnerability.