HIGH · 7.2

CVE-2014-9632

The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations,...

Vulnerability Description

The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AvgProtection>= 2015, <= 2015.5314
AvgInternet Security>= 2013, < 2013.3495

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9632?

CVE-2014-9632 is a vulnerability with a CVSS score of 7.2 (HIGH). The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations,...

How severe is CVE-2014-9632?

CVE-2014-9632 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9632?

Check the references section above for vendor advisories and patch information. Affected products include: Avg Protection, Avg Internet Security.