CVE-2024-13959

Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging the service to delete a directory
Configurations

No configuration.

History

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de escalada de privilegios locales mediante seguimiento de enlaces en TuneupSvc.exe en AVG TuneUp 24.2.16593.9844 en Windows permite a atacantes locales escalar privilegios y ejecutar código arbitrario en el contexto del SYSTEM mediante la creación de un enlace simbólico y el uso del servicio para eliminar un directorio.

09 May 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-09 16:15

Updated : 2025-05-12 17:32


NVD link : CVE-2024-13959

Mitre link : CVE-2024-13959

CVE.ORG link : CVE-2024-13959


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')