CVE-2018-12572

HIGH

Avast Free Antivirus <19.1.2360 - Info Disclosure

Title source: llm
STIX 2.1

Description

Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-312
Status published
Products (1)
avast/free_antivirus < 19.1.2360
Published Mar 21, 2019
Tracked Since Feb 18, 2026