First published: Mon Oct 17 2022(Updated: )
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.
Credit: security@nortonlifelock.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avira Avira Security | <=1.1.71.30554 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3368 is a vulnerability within the Software Updater functionality of Avira Security for Windows that allows an attacker to escalate privileges.
CVE-2022-3368 impacts Avira Security for Windows by allowing an attacker with write access to the filesystem to escalate their privileges.
CVE-2022-3368 has a severity score of 8.8 (High).
You can fix CVE-2022-3368 by updating Avira Security to version 1.1.72.30556 or later.
You can find more information about CVE-2022-3368 at the following reference: [https://support.norton.com/sp/static/external/tools/security-advisories.html](https://support.norton.com/sp/static/external/tools/security-advisories.html)