Vulnerabilities

10 year old vulnerabilities discovered in Avast, AVG antivirus software

0

Two high-severity vulnerabilities were disclosed in Avast and AVG antivirus products which were left undetected for ten years.
SentinelOne published a security advisory on the bugs that has been dubbed as CVE-2022-26522 and CVE-2022-26523.

According to the researchers at the cybersecurity firm, the vulnerabilities have existed since 2012 and, hence it could have affected more than millions of users worldwide.

CVE-2022-26522 and CVE-2022-26523 were found in the Avast Anti Rootkit driver that was introduced in January 2012 and also used by AVG. The vulnerability, CVE-2022-26522 was present in a socket connection handler used by the kernel driver aswArPot.sys, and an attacker could hijack a variable to escalate privileges.

Security products must run with high privilege levels, and the attackers who can exploit this flaw could potentially disable security solutions, tamper with a target operating system, or perform other malicious actions.

The second vulnerability, CVE-2022-26523, is also similar to the first one and was present in the aswArPot+0xc4a3 function.

The researchers stated that due to the nature of these vulnerabilities, they can be triggered from sandboxes and might be exploitable in contexts other than just local privilege escalation.

SentinelLabs reported the vulnerabilities to Avast on December 20, 2021. Avast had acknowledged the report by January 4th and released fixes in Avast v.22.1 to deal with the vulnerabilities after triage. The vulnerabilities were patched by February 11.

The cybersecurity solutions provider assured that there is no evidence of active exploitation in the wild and all the users must have received the necessary updates automatically and do not need to take further action.

They recommends their Avast and AVG users to constantly update their software to the latest version to stay protected.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Pro-Ukraine attackers launch DDoS attacks on Russian sites

Previous article

Google to bring Passwordless Authentication Support to Android and Chrome

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *