ZDI-25-707: AVG TuneUp for PC TuneUp Service Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of AVG TuneUp for PC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13960.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-707?
ZDI-25-707 has been assigned a CVSS rating indicating a significant security risk related to privilege escalation.
How do I fix ZDI-25-707?
To mitigate ZDI-25-707, users should update AVG TuneUp for PC to the latest version provided by the vendor.
Who is affected by ZDI-25-707?
ZDI-25-707 affects installations of AVG TuneUp for PC that are vulnerable to local privilege escalation.
What type of vulnerability is ZDI-25-707?
ZDI-25-707 is a local privilege escalation vulnerability that allows low-privileged users to gain higher-level access.
What is required to exploit ZDI-25-707?
An attacker must first execute low-privileged code on the target system to exploit the ZDI-25-707 vulnerability.