CVE Feed

    Dashboard / CVE / CVE-2019-11230

    CVE-2019-11230

    In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

    Published:Jul 18, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 18, 2019
    EPSS Score:0.00112
    CVSS Score:4.4

    Affected Products

    Vendor
    Avast
    Product
    Antivirus

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High