CVE-2026-27749: Avira Internet Security System Speedup Insecure Deserialization
Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input validation or deserialization safeguards. Because the file can be created or modified by a local user in default configurations, an attacker can supply a crafted serialized payload that is deserialized by the privileged process, resulting in arbitrary code execution as SYSTEM.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27749?
CVE-2026-27749 has a high severity level due to the potential for remote code execution and privilege escalation.
How do I fix CVE-2026-27749?
To fix CVE-2026-27749, update to the latest version of Avira Internet Security that includes the security patch.
What components are affected by CVE-2026-27749?
CVE-2026-27749 affects the System Speedup component of Avira Internet Security.
Can CVE-2026-27749 be exploited remotely?
Yes, CVE-2026-27749 could potentially be exploited remotely due to the insecure deserialization of untrusted data.
What are the potential consequences of exploiting CVE-2026-27749?
Exploiting CVE-2026-27749 may allow attackers to execute arbitrary code with SYSTEM privileges.