CVE-2023-1585: Medium severity avast antivirus vulnerability
Published Apr 19, 2023
·Updated
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG Antivirus version 22.11 and virus definitions from 14 February 2023 or later.
Affected Software
3 affected components
Avast Antivirus>=22.5<22.11
AVG Anti-Virus>=22.5<22.11
Microsoft Windows
Event History
Apr 19, 2023
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-1585.
2
What is the severity rating of CVE-2023-1585?
The severity rating of CVE-2023-1585 is medium, with a value of 6.3.
3
Which software versions are affected by CVE-2023-1585?
Avast Antivirus and AVG Anti-Virus versions between 22.5 and 22.11 are affected by CVE-2023-1585.
4
How can I fix CVE-2023-1585?
To fix CVE-2023-1585, update Avast and AVG Antivirus to version 22.11 and ensure virus definitions from 14 February 2023 or later are installed.
5
Is Microsoft Windows affected by CVE-2023-1585?
No, Microsoft Windows is not affected by CVE-2023-1585.