CVE-2024-7229: (0Day) Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability
Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22892.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7229?
CVE-2024-7229 is classified as a high severity vulnerability due to its potential to allow local privilege escalation.
How do I fix CVE-2024-7229?
To fix CVE-2024-7229, update Avast Cleanup Premium to the latest version where the vulnerability has been addressed.
Who is affected by CVE-2024-7229?
CVE-2024-7229 affects installations of Avast Cleanup Premium version 23.4 build 15592.
What are the exploitation conditions for CVE-2024-7229?
An attacker must first have the ability to execute low-privileged code on the target system to exploit CVE-2024-7229.
What type of vulnerability is CVE-2024-7229?
CVE-2024-7229 is a local privilege escalation vulnerability, allowing unauthorized users to gain higher privileges.