CVE-2020-10861

HIGH

Avast Antivirus < 20.0 - Arbitrary File Deletion via aswTask RPC Endpoint

Title source: llm
STIX 2.1

Description

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avast Program Path via RPC, when Self Defense is Enabled.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://forum.avast.com/index.php?topic=232420.0
Release Notes, Vendor Advisory x_refsource_misc
https://forum.avast.com/index.php?topic=232423.0

Scores

CVSS v3 7.5
EPSS 0.0165
EPSS Percentile 73.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (1)
avast/antivirus < 20.0
Published Apr 01, 2020
Tracked Since Feb 18, 2026