Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54468 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack. |
Solution
Update to Avast Cleanup Premium 24.3.17165.19178 or newer
Workaround
No workaround given by the vendor.
Fri, 09 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack. | |
| Title | Avast Cleanup Premium TuneupSvc Link Following Local Privilege Escalation Vulnerability | |
| Weaknesses | CWE-367 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NLOK
Published:
Updated: 2025-05-09T17:38:53.172Z
Reserved: 2025-05-09T14:44:31.333Z
Link: CVE-2024-13961
Updated: 2025-05-09T17:22:57.379Z
Status : Awaiting Analysis
Published: 2025-05-09T16:15:23.583
Modified: 2025-05-12T17:32:32.760
Link: CVE-2024-13961
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:51Z
EUVD