CVE-2016-4025 describes a vulnerability in multiple Avast security products, including various versions of Internet Security, Pro Antivirus, Premier, Free Antivirus, Business Security, Endpoint Protection suites, File Server Security, and Email Server Security. This medium-severity vulnerability (CVSS 5.5) allows a local attacker to bypass the DeepScreen feature through a DeviceIoControl call, potentially leading to a high impact on integrity without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.2241CPE matchmatch criteria | cpe:2.3:a:avast:business_security:11.1.2241:*:*:*:*:*:*:* | ||
11.1.2245CPE matchmatch criteria | cpe:2.3:a:avast:business_security:11.1.2245:*:*:*:*:*:*:* | ||
11.1.2253CPE matchmatch criteria | cpe:2.3:a:avast:business_security:11.1.2253:*:*:*:*:*:*:* | ||
11.1.2260CPE matchmatch criteria | cpe:2.3:a:avast:business_security:11.1.2260:*:*:*:*:*:*:* | ||
11.1.2261CPE matchmatch criteria | cpe:2.3:a:avast:business_security:11.1.2261:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.