First published: Thu Oct 03 2024(Updated: )
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
Credit: security@nortonlifelock.com
Affected Software | Affected Version | How to fix |
---|---|---|
AVG Antivirus Plus Firewall | <24.1 | |
Avast Antivirus | <24.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5803 is considered a high severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2024-5803, update AVG or Avast Antivirus to version 24.1 or later where this vulnerability is addressed.
CVE-2024-5803 affects users of AVG and Avast Antivirus prior to version 24.1.
CVE-2024-5803 allows a local attacker to escalate privileges via a COM hijack exploit when self-protection is disabled.
TOCTOU refers to a time-of-check to time-of-use vulnerability that can be exploited when self-protection features are turned off.