Vulnerability Description
Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input validation or deserialization safeguards. Because the file can be created or modified by a local user in default configurations, an attacker can supply a crafted serialized payload that is deserialized by the privileged process, resulting in arbitrary code execution as SYSTEM.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avira | Internet Security | < 1.1.114.3113 |
Related Weaknesses (CWE)
References
- https://support.avira.com/hc/en-us/articles/360010656158-Current-Avira-versionsRelease Notes
- https://www.avira.com/en/internet-securityProduct
- https://www.gendigital.com/us/en/contact-us/security-advisories/
FAQ
What is CVE-2026-27749?
CVE-2026-27749 is a vulnerability with a CVSS score of 7.8 (HIGH). Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privil...
How severe is CVE-2026-27749?
CVE-2026-27749 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-27749?
Check the references section above for vendor advisories and patch information. Affected products include: Avira Internet Security.