CVE-2009-1784

UnknownEPSS 3.41%

Last modified

CVE-2009-1784 is a vulnerability of currently unknown severity. The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.. EPSS estimates a 3.41% chance of exploitation in the next 30 days.

Description

The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.

Metrics

EPSS Probability
3.41%

87.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AvgAvg Anti-Virus<= 8.0.156
AvgAvg Anti-Virus6.0.710
AvgAvg Anti-Virus7.0
AvgAvg Anti-Virus7.0.251
AvgAvg Anti-Virus7.0.323
AvgAvg Anti-Virus7.1.308
AvgAvg Anti-Virus7.1.407
AvgAvg Anti-Virus7.5.51
AvgAvg Anti-Virus7.5.448
AvgAvg Anti-Virus7.5.476
AvgAvg Anti-Virus8.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-1784?
The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.
How severe is CVE-2009-1784?
Severity scoring for CVE-2009-1784 is pending analysis. The EPSS model estimates a 3.41% probability of exploitation in the next 30 days.
How do I fix CVE-2009-1784?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-1784?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST