CVE-2015-8620

Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
avastavast_free_antivirus
𝑥
≤ 11.1.2245
avastavast_internet_security
𝑥
≤ 11.1.2245
avastavast_premier
𝑥
≤ 11.1.2245
avastavast_pro_antivirus
𝑥
≤ 11.1.2245
𝑥
= Vulnerable software versions