Multiple Avira AntiVir Products 'CreateProcess()' Local Privilege Escalation Vulnerabilty

BID:33291

Info

Multiple Avira AntiVir Products 'CreateProcess()' Local Privilege Escalation Vulnerabilty

Bugtraq ID: 33291
Class: Input Validation Error
CVE:
Remote: No
Local: Yes
Published: Jan 15 2009 12:00AM
Updated: Jan 16 2009 11:42PM
Credit: Thierry Zoller
Vulnerable: AVIRA Premium Security Suite 0
AVIRA AntiVir Professional 0
AVIRA AntiVir Premium 0
Not Vulnerable:

Discussion

Multiple Avira AntiVir Products 'CreateProcess()' Local Privilege Escalation Vulnerabilty

Multiple Avira products are prone to a local privilege-escalation vulnerability because they insecurely make a 'CreateProcess()' API function call.

A local attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges, which may facilitate a complete compromise of the affected computer.

The following applications are vulnerable:

Avira AntiVir Premium
Avira Premium Security Suite
Avira AntiVir Professional

Exploit / POC

Multiple Avira AntiVir Products 'CreateProcess()' Local Privilege Escalation Vulnerabilty

A local attacker can use readily available tools to exploit this issue.

Solution / Fix

Multiple Avira AntiVir Products 'CreateProcess()' Local Privilege Escalation Vulnerabilty

Solution:
Vendor updates are available. Contact the vendor for more information.

References

Multiple Avira AntiVir Products 'CreateProcess()' Local Privilege Escalation Vulnerabilty

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report