First published: Wed Oct 23 2019(Updated: )
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that use WMI, e.g., AVGSvc.exe 19.6.4546.0 and TuneupSmartScan.dll 19.1.884.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast AntiVirus | <19.8 | |
AVG Anti-Virus | <19.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-17093.
The severity of CVE-2019-17093 is high with a CVSS score of 7.8.
Avast antivirus versions before 19.8 and AVG antivirus versions before 19.8 are affected by CVE-2019-17093.
CVE-2019-17093 allows an attacker to implant a malicious DLL into a protected-light process, potentially bypassing some self-defense mechanisms.
Update Avast antivirus and AVG antivirus to version 19.8 or higher to mitigate the DLL Preloading vulnerability.