ZDI-25-698: Avast Cleanup Premium TuneupSvc Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13962.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-698?
The severity of ZDI-25-698 is classified as high due to its potential for local privilege escalation.
How do I fix ZDI-25-698?
To fix ZDI-25-698, ensure that you have the latest version of Avast Cleanup Premium installed, as updates often contain security patches.
Who is affected by ZDI-25-698?
ZDI-25-698 affects users of Avast Cleanup Premium who have not implemented necessary security measures to restrict local execution of code.
What type of vulnerability is ZDI-25-698?
ZDI-25-698 is classified as a local privilege escalation vulnerability.
Can ZDI-25-698 be exploited remotely?
No, ZDI-25-698 requires an attacker to have local access to the system to exploit the vulnerability.