Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/151590/Avast-Anti-Virus-Local-Credential-Disclosure.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2019-03-21 09:00
Updated : 2020-08-24 10:37
NVD link : CVE-2018-12572
Mitre link : CVE-2018-12572
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
avast
- free_antivirus