ZDI-23-1474: (0Day) Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of the sandbox feature. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code outside the sandbox at medium integrity.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2023-42124.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1474?
The severity of ZDI-23-1474 is categorized as a privilege escalation vulnerability.
How do I fix ZDI-23-1474?
To fix ZDI-23-1474, update your Avast Premium Security to the latest version.
Who is affected by ZDI-23-1474?
ZDI-23-1474 affects installations of Avast Premium Security on local systems.
What type of vulnerability is ZDI-23-1474?
ZDI-23-1474 is a privilege escalation vulnerability that allows local attackers to gain higher system privileges.
What is required to exploit ZDI-23-1474?
An attacker must have the ability to execute low-privileged code on the system to exploit ZDI-23-1474.