CVE-2024-13960
Last modified
CVE-2024-13960 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-13960?
How severe is CVE-2024-13960?
How do I fix CVE-2024-13960?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-139552nd Order SQL injection vulnerabilities in ASPECT allow unin…9.4
- CVE-2024-13956SSL Verification Bypass vulnerabilities exist in ASPECT if a…8.8
- CVE-2024-13957SSRF Server Side Request Forgery vulnerabilities exist in AS…7.6
- CVE-2024-13958Stored Cross Site Scripting vulnerabilities exist in ASPECT …4.8
- CVE-2024-13959Link Following Local Privilege Escalation Vulnerability in T…7.8
- CVE-2024-1396The Shortcodes and extra features for Phlox theme plugin for…5.4
- CVE-2024-13961Link Following Local Privilege Escalation Vulnerability in T…7.8
- CVE-2024-13962Link Following Local Privilege Escalation Vulnerability in T…7.8
- CVE-2024-13964Rejected reason: wrong year
- CVE-2024-13965Rejected reason: wrong year
- CVE-2024-13966ZKTeco BioTime allows unauthenticated attackers to enumerate…7.3
- CVE-2024-13967This vulnerability allows the successful attacker to gain un…9.4
Are you affected by CVE-2024-13960?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
