CVE-2025-71326: AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that execute with high-level system permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the AVAST Antivirus 25.11 SecureLine unquoted service path privilege escalation by ensuring the SecureLine service’s binary path in the service configuration is quoted/properly bounded to prevent untrusted path injection (so local users cannot execute malicious binaries with elevated SYSTEM privileges).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71326?
CVE-2025-71326 has a high severity rating of 8.5.
How do I fix CVE-2025-71326?
To fix CVE-2025-71326, ensure that the service paths in Avast Antivirus are quoted correctly.
What version of Avast is affected by CVE-2025-71326?
CVE-2025-71326 specifically affects Avast Antivirus version 25.11.
What type of vulnerability is CVE-2025-71326?
CVE-2025-71326 is an unquoted service path privilege escalation vulnerability.
Who can be impacted by CVE-2025-71326?
Local non-privileged users can be impacted by CVE-2025-71326, as it allows them to execute code with elevated SYSTEM privileges.