An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST1 | third party advisory |
https://forum.avast.com/index.php?topic=317641.0 | vendor advisory |