CVE-2024-5803: Local privelage escalation via COM hijacking
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5803?
CVE-2024-5803 is considered a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2024-5803?
To fix CVE-2024-5803, update AVG or Avast Antivirus to version 24.1 or later where this vulnerability is addressed.
Who is affected by CVE-2024-5803?
CVE-2024-5803 affects users of AVG and Avast Antivirus prior to version 24.1.
What kind of attack does CVE-2024-5803 enable?
CVE-2024-5803 allows a local attacker to escalate privileges via a COM hijack exploit when self-protection is disabled.
What does TOCTOU mean in the context of CVE-2024-5803?
TOCTOU refers to a time-of-check to time-of-use vulnerability that can be exploited when self-protection features are turned off.