First published: Thu Oct 10 2019(Updated: )
** DISPUTED ** Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avira Software Updater | <2.0.6.21094 | |
<2.0.6.21094 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-17449.
The severity of CVE-2019-17449 is medium with a CVSS score of 6.7.
The affected software is Avira Software Updater version up to 2.0.6.21094.
CVE-2019-17449 is a DLL side-loading attack vulnerability in Avira Software Updater that allows an attacker with administrator privileges to gain SYSTEM privileges.
The vendor disputes the validity of CVE-2019-17449, stating that exploiting it would require at least administrator privileges and would gain only SYSTEM privileges.