Skip to main content

Vendor archive

avast CVEs

Beta · best-effort

75 CVEs tagged to vendor avast8 Critical, 40 High, 26 Medium, 1 Low, 0 Unrated.

CVE-2025-3500

Published Dec 1, 2025

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13032

Published Nov 11, 2025

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-7233

Published Nov 22, 2024

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7232

Published Nov 22, 2024

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7231

Published Nov 22, 2024

Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7230

Published Nov 22, 2024

Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7229

Published Nov 22, 2024

Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7228

Published Nov 22, 2024

Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7227

Published Nov 22, 2024

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9484

Published Oct 4, 2024

An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application du…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9483

Published Oct 4, 2024

A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9482

Published Oct 4, 2024

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application dur…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9481

Published Oct 4, 2024

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5102

Published Jun 10, 2024

A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORI…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42125

Published May 3, 2024

Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42124

Published May 3, 2024

Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5760

Published Nov 8, 2023

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be furthe…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-20118

Published Jul 11, 2023

Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4291

Published Dec 8, 2022

The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4173

Published Dec 6, 2022

A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-28965

Published May 20, 2022

Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before v21.11.2500 allows attackers to execute arbitrary code or c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3