CVE-2022-3368

A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.
Configurations

Configuration 1 (hide)

cpe:2.3:a:avira:avira_security:*:*:*:*:*:windows:*:*

History

10 May 2025, 03:15

Type Values Removed Values Added
CWE CWE-276

21 Nov 2024, 07:19

Type Values Removed Values Added
References () https://support.norton.com/sp/static/external/tools/security-advisories.html - Vendor Advisory () https://support.norton.com/sp/static/external/tools/security-advisories.html - Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.3

Information

Published : 2022-10-17 21:15

Updated : 2025-05-10 03:15


NVD link : CVE-2022-3368

Mitre link : CVE-2022-3368

CVE.ORG link : CVE-2022-3368


JSON object : View

Products Affected

avira

  • avira_security
CWE
NVD-CWE-noinfo CWE-276

Incorrect Default Permissions