CVE-2016-4025

UnknownEPSS 0.39%

Last modified

CVE-2016-4025 is a vulnerability of currently unknown severity. Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.

Description

Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.

Metrics

EPSS Probability
0.39%

30.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AvastBusiness Security11.1.2241
AvastBusiness Security11.1.2245
AvastBusiness Security11.1.2253
AvastBusiness Security11.1.2260
AvastBusiness Security11.1.2261
AvastBusiness Security11.1.2262
AvastFree Antivirus11.1.2241
AvastFree Antivirus11.1.2245
AvastFree Antivirus11.1.2253
AvastFree Antivirus11.1.2260
AvastFree Antivirus11.1.2261
AvastFree Antivirus11.1.2262
AvastInternet Security11.1.2241
AvastInternet Security11.1.2245
AvastInternet Security11.1.2253
AvastInternet Security11.1.2260
AvastInternet Security11.1.2261
AvastInternet Security11.1.2262
AvastPremier11.1.2241
AvastPremier11.1.2245
AvastPremier11.1.2253
AvastPremier11.1.2260
AvastPremier11.1.2261
AvastPremier11.1.2262
AvastPro Antivirus11.1.2241
AvastPro Antivirus11.1.2245
AvastPro Antivirus11.1.2253
AvastPro Antivirus11.1.2260
AvastPro Antivirus11.1.2261
AvastPro Antivirus11.1.2262
AvastEmail Server Security<= 8.0.1609
AvastEmail Server Security8.0.1606
AvastEndpoint Protection<= 8.0.1609
AvastEndpoint Protection8.0.1606
AvastEndpoint Protection Plus8.0.1606
AvastEndpoint Protection Plus8.0.1609
AvastEndpoint Protection Suite<= 8.0.1609
AvastEndpoint Protection Suite8.0.1606
AvastEndpoint Protection Suite Plus<= 8.0.1609
AvastEndpoint Protection Suite Plus8.0.1606
AvastFile Server Security<= 8.0.1609
AvastFile Server Security8.0.1606

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-4025?
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.
How severe is CVE-2016-4025?
Severity scoring for CVE-2016-4025 is pending analysis. The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2016-4025?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-4025?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST