Vulnerability Description
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to turn off this feature. After that, one can construct an event that will modify a file at a specific location, and pass this event to the driver, thereby defeating the anti-virus functionality.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avira | Free Antivirus | < 15.0.2004.1825 |
References
- https://support.avira.com/hc/en-us/articles/360000109798-Avira-Antivirus-for-WinRelease NotesVendor Advisory
- https://support.avira.com/hc/en-us/articles/360000109798-Avira-Antivirus-for-WinRelease NotesVendor Advisory
FAQ
What is CVE-2020-8961?
CVE-2020-8961 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to tur...
How severe is CVE-2020-8961?
CVE-2020-8961 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-8961?
Check the references section above for vendor advisories and patch information. Affected products include: Avira Free Antivirus.