CVE-2020-10862

HIGH

Avast Antivirus <20 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Local Privilege Escalation (LPE) via RPC.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://forum.avast.com/index.php?topic=232420.0
Release Notes, Vendor Advisory x_refsource_misc
https://forum.avast.com/index.php?topic=232423.0

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 34.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
avast/antivirus < 20.0
Published Apr 01, 2020
Tracked Since Feb 18, 2026