CVE-2024-7235: AVG AntiVirus Free Link Following Denial-of-Service Vulnerability
AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. . Was ZDI-CAN-22803.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7235?
CVE-2024-7235 is classified as a denial-of-service vulnerability with local exploitability.
How do I fix CVE-2024-7235?
To fix CVE-2024-7235, users should update to the latest version of AVG AntiVirus Free that addresses this vulnerability.
What systems are affected by CVE-2024-7235?
CVE-2024-7235 affects AVG AntiVirus Free version 23.11.8635.809.
Who can exploit CVE-2024-7235?
CVE-2024-7235 can be exploited by local attackers who are able to execute low-privileged code on the affected system.
What type of vulnerability is CVE-2024-7235?
CVE-2024-7235 is a denial-of-service vulnerability that can disrupt the normal operations of AVG AntiVirus Free.