cve/2018/CVE-2018-12572.md

19 lines
819 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-12572](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12572)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
### POC
#### Reference
- http://packetstormsecurity.com/files/151590/Avast-Anti-Virus-Local-Credential-Disclosure.html
2024-06-09 00:33:16 +00:00
- http://packetstormsecurity.com/files/151590/Avast-Anti-Virus-Local-Credential-Disclosure.html
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.