CVE-2022-4173

HIGH

Avast and AVG Antivirus 20.5-22.9 - Privilege Escalation via Malware Removal Functionality

Title source: llm
STIX 2.1

Description

A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0068
EPSS Percentile 47.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (2)
avast/avast 20.5 - 22.9
avast/avg_antivirus 20.5 - 22.9
Published Dec 06, 2022
Tracked Since Feb 18, 2026