Skip to main content

Vendor/product archive

avast / antivirus CVEs

Beta · best-effort

32 CVEs tagged to avast / antivirus4 Critical, 16 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2025-3500

Published Dec 1, 2025

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13032

Published Nov 11, 2025

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9484

Published Oct 4, 2024

An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application du…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9483

Published Oct 4, 2024

A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9482

Published Oct 4, 2024

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application dur…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9481

Published Oct 4, 2024

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5102

Published Jun 10, 2024

A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORI…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-20118

Published Jul 11, 2023

Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45339

Published Dec 27, 2021

Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassin…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45338

Published Dec 27, 2021

Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45337

Published Dec 27, 2021

Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45336

Published Dec 27, 2021

Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed code to gain elevated privileges by using system IPC interfac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45335

Published Dec 27, 2021

Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15024

Published Sep 10, 2020

An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows mai…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10868

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10867

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended acces…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10866

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10865

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary change…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10864

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a reboot via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10863

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10862

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Local Privile…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2