CVE-2024-7228: (0Day) Avast Free Antivirus Link Following Denial-of-Service Vulnerability
Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-22806.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7228?
CVE-2024-7228 has a medium severity rating due to its potential to cause denial-of-service conditions.
How do I fix CVE-2024-7228?
To fix CVE-2024-7228, update Avast Free Antivirus to the latest version recommended by the vendor.
What type of vulnerability is CVE-2024-7228?
CVE-2024-7228 is a denial-of-service vulnerability that affects Avast Free Antivirus.
Who is affected by CVE-2024-7228?
CVE-2024-7228 affects all installations of Avast Free Antivirus prior to the latest security patch.
Can CVE-2024-7228 be exploited remotely?
No, CVE-2024-7228 requires local access or the ability to execute low-privileged code on the target machine to be exploited.