ZDI-23-1475: (0Day) Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of the sandbox feature. By creating a symbolic link, an attacker can abuse the service to create arbitrary namespace objects. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-42125.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1475?
The severity of ZDI-23-1475 is classified as a privilege escalation vulnerability.
How do I fix ZDI-23-1475?
To fix ZDI-23-1475, ensure that you have the latest version of Avast Premium Security installed, which includes the necessary security patches.
Who is affected by ZDI-23-1475?
ZDI-23-1475 affects users of Avast Premium Security who have not applied the latest updates.
What type of attack does ZDI-23-1475 enable?
ZDI-23-1475 enables local attackers to escalate their privileges on a vulnerable system.
What is required to exploit ZDI-23-1475?
To exploit ZDI-23-1475, an attacker must first execute low-privileged code on the affected system.