A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58045 A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.
Fixes

Solution

We encourage customers to ensure their security software is always updated to the latest version available.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: NLOK

Published:

Updated: 2024-09-03T20:20:38.486Z

Reserved: 2023-10-25T00:31:22.790Z

Link: CVE-2023-5760

cve-icon Vulnrichment

Updated: 2024-08-02T08:07:32.642Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T17:15:07.993

Modified: 2024-11-21T08:42:25.890

Link: CVE-2023-5760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.