CVE-2017-8307 is a critical vulnerability affecting Avast Antivirus versions prior to v17, allowing unprivileged users to launch binaries, or replace/delete arbitrary files via the AvastSVC.exe LPC interface. This flaw, with a CVSS score of 9.8, can lead to denial of service and facilitate hiding attack traces, particularly when Avast Self-Defense is disabled or combined with CVE-2017-8308. Despite its high severity, there is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.3.2279CPE matchmatch criteria | cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.