First published: Fri May 09 2025(Updated: )
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
Credit: security@nortonlifelock.com
Affected Software | Affected Version | How to fix |
---|---|---|
Norton Utilities Ultimate | ||
Avast Cleanup Premium | ||
AVG TuneUp |
Upgrade to the below versions, or newer, released 19/Dec/2024 * Norton Utilities 24.3 SU1 - 24.3.17165.6812 * Avast Cleanup 24.3-SU1 - 24.3.17165.19178 * AVG TuneUp 24.3-SU1 - 24.3.17165.10564
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13944 is rated as a high-severity local privilege escalation vulnerability.
To fix CVE-2024-13944, update Norton Utilities Ultimate to the latest version available.
CVE-2024-13944 affects users of Norton Utilities Ultimate on Windows 10 Pro x64.
CVE-2024-13944 is a local privilege escalation vulnerability that allows attackers to execute arbitrary code.
No, CVE-2024-13944 requires local access to the vulnerable system to escalate privileges.