### [CVE-2024-5803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5803) ![](https://img.shields.io/static/v1?label=Product&message=Antivirus&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C24.1%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-367%20Time-of-check%20Time-of-use%20(TOCTOU)%20Race%20Condition&color=brighgreen) ### Description The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled. ### POC #### Reference - https://support.norton.com/sp/static/external/tools/security-advisories.html #### Github No PoCs found on GitHub currently.