ZDI-25-695: AVG TuneUp for PC TuneupSvc Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of AVG TuneUp for PC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13944.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-695?
The ZDI-25-695 vulnerability has been assigned a CVSS rating that indicates it poses a significant risk of privilege escalation.
How do I fix ZDI-25-695?
To remediate ZDI-25-695, users should update AVG TuneUp for PC to the latest version provided by AVG.
Who is affected by ZDI-25-695?
ZDI-25-695 affects installations of AVG TuneUp for PC that have not been updated to a secure version.
What type of vulnerability is ZDI-25-695?
ZDI-25-695 is a local privilege escalation vulnerability that requires low-privileged code execution for exploitation.
Can ZDI-25-695 be exploited remotely?
No, ZDI-25-695 can only be exploited by local attackers with prior access to execute low-privileged code.