Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/151590/Avast-Anti-Virus-Local-Credential-Disclosure.html | third party advisory vdb entry exploit |