VulnerabilityModified
CVE-2020-13657
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links.
MEDIUM 5.5EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control of arbitrary files.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- avast/avg antivirus · avast/free antivirus
- Source
- cve@mitre.org
References
- https://forum.avast.com/index.php?topic=232423.0Release Notes, Vendor Advisory
- https://forum.avast.com/index.php?topic=234638.0Vendor Advisory
- https://forum.avast.com/index.php?topic=232423.0Release Notes, Vendor Advisory
- https://forum.avast.com/index.php?topic=234638.0Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.