CVE-2026-27749 is a high-severity deserialization of untrusted data vulnerability in the System Speedup component of Avira Internet Security. A local attacker can exploit this flaw by crafting a malicious serialized payload in a specific file path, which is then deserialized by a SYSTEM-privileged process without validation, leading to arbitrary code execution as SYSTEM. The vulnerability has a CVSS score of 7.8, indicating high impact on confidentiality, integrity, and availability. There is currently no public exploit code, active exploitation, or significant community discussion reported for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.114.3113CPE matchmatch criteria | cpe:2.3:a:avira:internet_security:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.