CVE-2016-4025
https://notcve.org/view.php?id=CVE-2016-4025
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call. Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x y Email Server Security v8.x.x permiten a atacantes eludir la funcionalidad DeepScreen a través de una llamada DeviceIoControll. • https://labs.nettitude.com/blog/escaping-avast-sandbox-using-single-ioctl-cve-2016-4025 • CWE-254: 7PK - Security Features •
CVE-2015-8620
https://notcve.org/view.php?id=CVE-2015-8620
Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request. Desbordamiento de buffer basado en memoria dinámica en el controlador de virtualización de Avast (aswSnx.sys) en Avast Internet Security, Pro Antivirus, Premier y Free Antivirus en versiones anteriores a 11.1.2253 permite a usuarios locales obtener privilegios a través de una ruta de archivo Unicode en una petición IOCTL. • http://packetstormsecurity.com/files/135859/Avast-11.1.2245-Heap-Overflow.html http://seclists.org/fulldisclosure/2016/Feb/94 http://www.securitytracker.com/id/1035093 https://www.nettitude.co.uk/exploiting-a-kernel-paged-pool-buffer-overflow-in-avast-virtualization-driver • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-5662
https://notcve.org/view.php?id=CVE-2015-5662
Directory traversal vulnerability in Avast before 150918-0 allows remote attackers to delete or write to arbitrary files via a crafted entry in a ZIP archive. Vulnerabilidad de salto de directorio en Avast en versiones anteriores a 150918-0 permite a atacantes remotos borrar o escribir en archivos arbitrarios a través de una entrada manipulada en un archivo ZIP • http://jvn.jp/en/jp/JVN25576608/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2015-000160 http://www.securitytracker.com/id/1033860 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2010-3126 – Avast! 5.0.594 - 'mfc90loc.dll' License Files DLL Hijacking
https://notcve.org/view.php?id=CVE-2010-3126
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc90loc.dll that is located in the same folder as an avast license (.avastlic) file. Vulnerabilidad de búsqueda en ruta no confiable en avast! Free Antivirus v5.0.594 y anteriores, permite a usuarios locales y posiblemente atacantes remotos, la ejecución de código de su elección y llevar a cabo ataques de secuestro de DLL a través de un troyano wab32.dll que está localizada en la misma carpeta como un archivo de licencia Avast (.avastlic). • https://www.exploit-db.com/exploits/14743 http://secunia.com/advisories/41109 http://www.exploit-db.com/exploits/14743 http://www.vupen.com/english/advisories/2010/2175 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7193 •
CVE-2010-0705 – Avast! 4.7 - 'aavmker4.sys' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2010-0705
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption. Aavmker4.sys en avast! desde v4.8 hasta v4.8.1368.0 y v5.0 anteriores a v5.0.418.0 corriendo sobre Windows 2000 o XP, no valida adecuadamente una entrada a IOCTL 0xb2d60030, lo que permite a usuarios locales producir una denegación de servicio (caída del sistema) o ejecutar código arbitrario para ganar privilegios a través de peticiones IOCTL utilizando direcciones de kernel manipuladas que inician una corrupción de memoria. • https://www.exploit-db.com/exploits/12406 http://forum.avast.com/index.php?topic=55484.0 http://osvdb.org/62510 http://secunia.com/advisories/38677 http://secunia.com/advisories/38689 http://www.securityfocus.com/archive/1/509710/100/0/threaded http://www.securityfocus.com/bid/38363 http://www.securitytracker.com/id?1023644 http://www.trapkit.de/advisories/TKADV2010-003.txt http://www.vupen.com/english/advisories/2010/0449 • CWE-20: Improper Input Validation •