CVE-2022-4173: Avast and AVG Antivirus for Windows vulnerable to Privilege Escalation
Published Dec 5, 2022
·Updated
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.
Affected Software
2 affected components
Avast Avast>=20.5<=22.9
Avast Avg Antivirus>=20.5<=22.9
Event History
Dec 5, 2022
CVE Published
via MITRE·11:15 PM
Data Sourced
via MITRE·11:15 PM
DescriptionSeverityWeakness
Dec 6, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4173?
CVE-2022-4173 is a vulnerability within the malware removal functionality of Avast and AVG Antivirus that allowed an attacker with write access to the filesystem to escalate their privileges.
2
How can an attacker exploit CVE-2022-4173?
An attacker with write access to the filesystem can exploit CVE-2022-4173 to escalate their privileges.
3
What is the severity of CVE-2022-4173?
CVE-2022-4173 has a severity rating of 8.8 (High).
4
Which software versions are affected by CVE-2022-4173?
Avast and AVG Antivirus versions up to 22.9 are affected by CVE-2022-4173.
5
How was CVE-2022-4173 fixed?
CVE-2022-4173 was fixed with Avast and AVG Antivirus version 22.10.