CVE-2022-28964: High severity avast premium security vulnerability
Published May 20, 2022
·Updated
An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.
Affected Software
1 affected component
Avast Premium Security<21.11.2500
Event History
May 20, 2022
CVE Published
via MITRE·01:13 AM
Data Sourced
via MITRE·01:13 AM
Description
Frequently Asked Questions
1
What is CVE-2022-28964?
CVE-2022-28964 is an arbitrary file write vulnerability in Avast Premium Security before version 21.11.2500 that allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.
2
How does CVE-2022-28964 affect Avast Premium Security?
CVE-2022-28964 affects Avast Premium Security before version 21.11.2500.
3
What is the severity of CVE-2022-28964?
The severity of CVE-2022-28964 is high with a CVSS score of 7.1.
4
How can an attacker exploit CVE-2022-28964?
An attacker can exploit CVE-2022-28964 by using a crafted DLL file to perform arbitrary file write and cause a Denial of Service (DoS).
5
Is there a fix available for CVE-2022-28964?
Yes, the fix for CVE-2022-28964 is to update Avast Premium Security to version 21.11.2500 or later.