First published: Wed Apr 19 2023(Updated: )
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus version 22.11
Credit: security@nortonlifelock.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avast AntiVirus | >=22.5<22.11 | |
AVG Anti-Virus | >=22.5<22.11 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1586 is a vulnerability found in Avast and AVG Antivirus for Windows that allows arbitrary file creation during the restore process.
CVE-2023-1586 has a severity rating of 4.7, which is considered medium.
Avast and AVG Antivirus versions between 22.5 and 22.11 for Windows are affected by CVE-2023-1586.
CVE-2023-1586 was fixed with Avast and AVG Antivirus version 22.11.
No, Microsoft Windows is not affected by CVE-2023-1586.