CVE-2023-1586: Medium severity avast antivirus vulnerability
Published Apr 19, 2023
·Updated
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus version 22.11
Affected Software
3 affected components
Avast Antivirus>=22.5<22.11
AVG Anti-Virus>=22.5<22.11
Microsoft Windows
Event History
Apr 19, 2023
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-1586?
CVE-2023-1586 is a vulnerability found in Avast and AVG Antivirus for Windows that allows arbitrary file creation during the restore process.
2
How severe is CVE-2023-1586?
CVE-2023-1586 has a severity rating of 4.7, which is considered medium.
3
Which software versions are affected by CVE-2023-1586?
Avast and AVG Antivirus versions between 22.5 and 22.11 for Windows are affected by CVE-2023-1586.
4
How was CVE-2023-1586 fixed?
CVE-2023-1586 was fixed with Avast and AVG Antivirus version 22.11.
5
Is Microsoft Windows affected by CVE-2023-1586?
No, Microsoft Windows is not affected by CVE-2023-1586.