- Description
- Grisoft AVG Free 7.1, and other versions including 7.0.308, sets Everyone/Full Control permissions for certain update files including (1) upd_vers.cfg, (2) incavi.avm, and (3) unspecified drivers, which might allow local users to gain privileges.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9876E4EA-9C93-4B3F-8E49-C34BB3CF5A5B"
},
{
"criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.0.251:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A2AD8F3-96E4-4F2F-87A2-786EE0672930"
},
{
"criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.0.323:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5188CBC-298E-4F5A-A817-2DB05B178D85"
},
{
"criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.1.308:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A38FC89B-5846-4693-A589-02C27E50A7F3"
}
],
"operator": "OR"
}
]
}
]