cve/2024/CVE-2024-5803.md
2025-09-29 16:08:36 +00:00

18 lines
789 B
Markdown

### [CVE-2024-5803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5803)
![](https://img.shields.io/static/v1?label=Product&message=Antivirus&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C24.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-367%20Time-of-check%20Time-of-use%20(TOCTOU)%20Race%20Condition&color=brighgreen)
### Description
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
### POC
#### Reference
- https://support.norton.com/sp/static/external/tools/security-advisories.html
#### Github
No PoCs found on GitHub currently.