CVE-2021-45337: High severity avast antivirus vulnerability
Published Dec 27, 2021
·Updated
Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing" process wscproxy.exe which could lead to acquire antimalware (AM-PPL) protection.
Affected Software
1 affected component
Avast Antivirus<20.8
Event History
Dec 27, 2021
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-45337?
CVE-2021-45337 is a privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to version 20.8.
2
How does CVE-2021-45337 work?
CVE-2021-45337 allows a local user with SYSTEM privileges to gain elevated privileges by 'hollowing' process wsc_proxy.exe.
3
What is the severity of CVE-2021-45337?
CVE-2021-45337 has a severity rating of 8.8 (high).
4
Which versions of Avast Antivirus are affected by CVE-2021-45337?
CVE-2021-45337 affects Avast Antivirus versions prior to 20.8.
5
How can I fix CVE-2021-45337?
To fix CVE-2021-45337, update Avast Antivirus to version 20.8 or later.