CVE-2020-12680
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collecting credentials stored in Chrome, Firefox, Opera, and Edge. The executable does not verify the calling program and thus a request such as fetchChromePasswords or fetchCredentials will succeed. NOTE: some third parties have stated that this is "not a vulnerability.
** EN DISPUTA ** Avira Free Antivirus versiones hasta 15.0.2005.1866, permite a usuarios locales detectar credenciales de usuario. Las funciones del archivo ejecutable Avira.PWM.NativeMessaging.exe están destinadas a recolectar credenciales almacenadas en Chrome, Firefox, Opera y Edge. El ejecutable no verifica el programa de llamada y así una petición tal y como fetchChromePasswords o fetchCredentials tendrá éxito. NOTA: algunos terceros han declarado que esto "no es una vulnerabilidad".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-06 CVE Reserved
- 2020-05-08 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://medium.com/%40knikolenko/avira-free-antivirus-password-collector-83452fa7f943 | X_refsource_misc | |
https://twitter.com/taviso/status/1258448515912491026 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Avira Search vendor "Avira" | Free Antivirus Search vendor "Avira" for product "Free Antivirus" | <= 15.0.2005.1866 Search vendor "Avira" for product "Free Antivirus" and version " <= 15.0.2005.1866" | - |
Affected
|