ZDI-25-025: Avira Prime System Speedup Service Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-9525.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-025?
The severity of ZDI-25-025 is rated at 7.8, indicating a high risk of privilege escalation.
How do I fix ZDI-25-025?
To fix ZDI-25-025, update Avira Prime to the latest version provided by the vendor, Avira.
Who is affected by ZDI-25-025?
ZDI-25-025 affects installations of Avira Prime where local attackers can potentially escalate their privileges.
What type of vulnerability is ZDI-25-025?
ZDI-25-025 is a privilege escalation vulnerability that allows local attackers to execute higher level permissions.
Can ZDI-25-025 be exploited remotely?
No, ZDI-25-025 can only be exploited locally by an attacker with low-privileged code execution capabilities.