CVE-2026-27748

HIGH

Avira Internet Security - Privilege Escalation

Title source: llm
STIX 2.1

Description

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. A local attacker can create a malicious link to redirect the delete operation to an arbitrary file, resulting in deletion of attacker-chosen files with SYSTEM privileges. This may lead to local privilege escalation, denial of service, or system integrity compromise depending on the targeted file and operating system configuration.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (3)
avira/internet_security < 1.1.114.3113
Gen Digital Inc./Avira Internet Security < 1.1.109.1990
Gen Digital Inc./Avira Internet Security 1.1.114.3113
Published Mar 05, 2026
Tracked Since Mar 05, 2026