CVE-2024-5102
Last modified
CVE-2024-5102 is a high-severity vulnerability rated 7/10 on the CVSS scale. A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the system files and make Windows callback to a specially-crafted file which could be used to launch a privileged shell instance. This issue affects Avast Antivirus prior to 24.2.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avast | Antivirus | < 24.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5102?
How severe is CVE-2024-5102?
How do I fix CVE-2024-5102?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-51014Netgear XR300 v1.0.3.78 was discovered to contain a stack ov…5.7
- CVE-2024-51015Netgear R7000P v1.3.3.154 was discovered to contain a comman…5.7
- CVE-2024-51016Netgear XR300 v1.0.3.78 was discovered to contain a stack ov…5.7
- CVE-2024-51017Netgear R7000P v1.3.3.154 was discovered to contain a stack …5.7
- CVE-2024-51018Netgear R7000P v1.3.3.154 was discovered to contain a stack …5.7
- CVE-2024-51019Netgear R7000P v1.3.3.154 was discovered to contain a stack …5.7
- CVE-2024-51020Netgear R7000P v1.3.3.154 was discovered to contain a stack …5.7
- CVE-2024-51021Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0…8
- CVE-2024-51022Netgear XR300 v1.0.3.78 was discovered to contain a stack ov…5.7
- CVE-2024-51023D-Link DIR_823G 1.0.2B05 was discovered to contain a command…8.8
- CVE-2024-51024D-Link DIR_823G 1.0.2B05 was discovered to contain a command…8
- CVE-2024-51026The NetAdmin IAM system (version 4.0.30319) has a Cross Site…5.4
Are you affected by CVE-2024-5102?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
