CVE-2022-4173
Last modified
CVE-2022-4173 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10. . EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avast | Avast | >= 20.5, <= 22.9 |
| Avast | Avg Antivirus | >= 20.5, <= 22.9 |
References
- https://support.norton.com/sp/static/external/tools/security-advisories.htmlThird Party Advisory
- https://support.norton.com/sp/static/external/tools/security-advisories.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4173?
How severe is CVE-2022-4173?
How do I fix CVE-2022-4173?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41724Large handshake records may cause panics in crypto/tls. Both…7.5
- CVE-2022-41725A denial of service is possible from excessive resource cons…7.5
- CVE-2022-41726Rejected reason: reserved but not needed
- CVE-2022-41727An attacker can craft a malformed TIFF image which will cons…5.5
- CVE-2022-41728Rejected reason: reserved but not needed
- CVE-2022-41729Rejected reason: reserved but not needed
- CVE-2022-41730Rejected reason: reserved but not needed
- CVE-2022-41731IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is …9.8
- CVE-2022-41732 IBM Maximo Mobile 8.7 and 8.8 stores user credentials in pl…5.5
- CVE-2022-41733 IBM InfoSphere Information Server 11.7 could allow a remote…5.3
- CVE-2022-41734IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow …7.5
- CVE-2022-41735IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0…6.1
Are you affected by CVE-2022-4173?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
