PoC Index

CVE-2018-12572

HIGH 7.8EPSS 0.3%

Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.

CVSS v3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.31% chance of exploitation in the next 30 days, 24th percentile
Published
2019-03-17
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related