Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.