CVE-2014-9632
Last modified
CVE-2014-9632 is a vulnerability of currently unknown severity. The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avg | Protection | >= 2015, <= 2015.5314 |
| Avg | Internet Security | >= 2013, < 2013.3495 |
| Avg | Internet Security | >= 2015, < 2015.5314 |
References
- http://packetstormsecurity.com/files/130248/AVG-Internet-Security-2015.0.5315-Privilege-Escalation.htmlExploit, Third Party Advisory
- http://www.avg.com/eu-en/avg-release-notesVendor Advisory
- http://www.exploit-db.com/exploits/35993Exploit, Third Party Advisory
- http://www.greyhathacker.net/?p=818Third Party Advisory
- http://www.osvdb.org/113824Broken Link
- http://packetstormsecurity.com/files/130248/AVG-Internet-Security-2015.0.5315-Privilege-Escalation.htmlExploit, Third Party Advisory
- http://www.avg.com/eu-en/avg-release-notesVendor Advisory
- http://www.exploit-db.com/exploits/35993Exploit, Third Party Advisory
- http://www.greyhathacker.net/?p=818Third Party Advisory
- http://www.osvdb.org/113824Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9632?
How severe is CVE-2014-9632?
How do I fix CVE-2014-9632?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-9625The GetUpdateFile function in misc/update.c in the Updater i…7.8
- CVE-2014-9626Integer underflow in the MP4_ReadBox_String function in modu…7.8
- CVE-2014-9627The MP4_ReadBox_String function in modules/demux/mp4/libmp4.…7.8
- CVE-2014-9628The MP4_ReadBox_String function in modules/demux/mp4/libmp4.…7.8
- CVE-2014-9629Integer overflow in the Encode function in modules/codec/sch…7.8
- CVE-2014-9630The rtp_packetize_xiph_config function in modules/stream_out…7.8
- CVE-2014-9633The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows…
- CVE-2014-9634Jenkins before 1.586 does not set the secure flag on session…
- CVE-2014-9635Jenkins before 1.586 does not set the HttpOnly flag in a Set…
- CVE-2014-9636unzip 6.0 allows remote attackers to cause a denial of servi…
- CVE-2014-9637GNU patch 2.7.2 and earlier allows remote attackers to cause…
- CVE-2014-9638oggenc in vorbis-tools 1.4.0 allows remote attackers to caus…
Are you affected by CVE-2014-9632?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
