Vulnerability Description
Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avira | Software Updater | < 2.0.6.21094 |
Related Weaknesses (CWE)
References
- https://safebreach.com/Post/Avira-Antivirus-2019-4-Services-DLL-Preloading-and-P
- https://support.avira.com/hc/en-us/articles/360000142857-Avira-Software-UpdaterRelease Notes
- https://safebreach.com/Post/Avira-Antivirus-2019-4-Services-DLL-Preloading-and-P
- https://support.avira.com/hc/en-us/articles/360000142857-Avira-Software-UpdaterRelease Notes
FAQ
What is CVE-2019-17449?
CVE-2019-17449 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privil...
How severe is CVE-2019-17449?
CVE-2019-17449 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17449?
Check the references section above for vendor advisories and patch information. Affected products include: Avira Software Updater.