CVE-2020-10867: Critical severity Avast Antivirus vulnerability
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10867?
The severity of CVE-2020-10867 is critical, with a severity score of 9.8.
How does CVE-2020-10867 affect Avast Antivirus?
CVE-2020-10867 affects Avast Antivirus versions up to and including version 20.0.
How can attackers exploit CVE-2020-10867?
Attackers can exploit CVE-2020-10867 by bypassing access restrictions on tasks from an untrusted process, when Self Defense is enabled in Avast Antivirus.
Are all versions of Microsoft Windows vulnerable to CVE-2020-10867?
No, only Avast Antivirus is affected by CVE-2020-10867. Microsoft Windows is not vulnerable.
Is there a fix available for CVE-2020-10867?
Yes, users should update Avast Antivirus to version 20.0 or higher to fix the vulnerability.