{ "id": "CVE-2019-11230", "sourceIdentifier": "cve@mitre.org", "published": "2019-07-18T17:15:11.880", "lastModified": "2019-07-24T15:33:25.357", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart." }, { "lang": "es", "value": "En Avast Antivirus antes de 19.4, un administrador local puede enga\u00f1ar al producto para que cambie el nombre de los archivos arbitrarios al reemplazar el archivo Logs \\ Update.log con un enlace simb\u00f3lico. La pr\u00f3xima vez que el producto intente escribir en el archivo de registro, se cambiar\u00e1 el nombre del destino del enlace simb\u00f3lico. Este defecto se puede aprovechar para cambiar el nombre de un archivo de producto cr\u00edtico (por ejemplo, AvastSvc.exe), lo que hace que el producto no se inicie en el pr\u00f3ximo reinicio del sistema." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE", "baseScore": 4.4, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 0.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:P", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 3.6 }, "baseSeverity": "LOW", "exploitabilityScore": 3.9, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-59" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:*", "versionEndExcluding": "19.4", "matchCriteriaId": "730BD260-2D89-42C7-B7F5-D3CE284A0571" } ] } ] } ], "references": [ { "url": "http://www.mcerlane.co.uk/CVE-2019-11230/", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "http://www.securityfocus.com/bid/109344", "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ] } ] }