CVE-2023-1900

HIGH

Avira Antivirus < 1.0.2303.633 - Denial of Service via Network Protection Feature

Title source: llm
STIX 2.1

Description

A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead to a denial-of-service situation. Issue was fixed with Endpointprotection.exe version 1.0.2303.633

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0030
EPSS Percentile 21.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (1)
avira/antivirus < 1.0.2303.633
Published Apr 19, 2023
Tracked Since Feb 18, 2026