Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1625

26
FAUCET Score

CVE-2008-1625 is a local privilege escalation vulnerability affecting avast! Home and Professional 4.7 for Windows. It stems from improper input validation in the aavmker4.sys driver when handling IOCTL 0xb2d60030 requests. With a CVSS score of 6.8, this vulnerability allows an authenticated local attacker to gain full control over the affected system, leading to complete compromise of confidentiality, integrity, and availability. While not actively exploited in the wild or on the CISA KEV catalog, public exploit code exists on ExploitDB, and it has a high FAUCET Risk Score of 85/100, indicating its potential impact despite limited community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.7.827CPE matchmatch criteria
cpe:2.3:a:avast:avast_antivirus_home:4.7.827:*:windows:*:*:*:*:*
4.7.844CPE matchmatch criteria
cpe:2.3:a:avast:avast_antivirus_home:4.7.844:*:windows:*:*:*:*:*
4.7.869CPE matchmatch criteria
cpe:2.3:a:avast:avast_antivirus_home:4.7.869:*:windows:*:*:*:*:*
4.7.1043CPE matchmatch criteria
cpe:2.3:a:avast:avast_antivirus_home:4.7.1043:*:windows:*:*:*:*:*
4.7.1098CPE matchmatch criteria
cpe:2.3:a:avast:avast_antivirus_home:4.7.1098:*:windows:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:L/AC:L/Au:S/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
3.1
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-12406 · Apr 27, 2010
This CVE's current EPSS score of 0.0071 is in the 95th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

secunia.com / advisories/29605
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/41527
avast.com / eng/avast-4-home_pro-revision-history.html
securityfocus.com / archive/1/490321/100/0/threaded
securityfocus.com / bid/28502
securitytracker.com / id
trapkit.de / advisories/TKADV2008-002.txt
vupen.com / english/advisories/2008/1034/references