CVE-2020-12254
published 2020-04-26CVE-2020-12254: Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.
PriorityP432high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
29.6th percentile
Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avira | antivirus | < 5.0.2003.1821 | 5.0.2003.1821 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Joomla Component Ek rishta 2.10 - SQL Injection 1
suricata·2018-06-26
CVE-2018-12254 ET WEB_SPECIFIC_APPS Joomla Component Ek rishta 2.10 - SQL Injection 1
ET WEB_SPECIFIC_APPS Joomla Component Ek rishta 2.10 - SQL Injection 1
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Joomla Component Ek rishta 2.10 - SQL Injection 1"; flow:established,to_server; http.uri; content:"home/requested_user/Sent interest/"; nocase; pcre:"/^(?:[a-zA-Z0-9_])*[\x2c\x22\x27\x28]/Ri"; reference:cve,2018-12254; reference:url,www.exploit-db.com/exploits/44869/; classtype:web-application-attack; sid:2025744; rev:4; metadata:affected_product Joomla, attack_target Web_Server, created_at 2018_06_26, cve CVE_2018_12254, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, updated_at 2020_08_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Ex
No public exploits indexed.
No writeups or analysis indexed.
http://web.archive.org/web/20200429193852/https://support.avira.com/hc/en-us/articles/360000109798-Avira-Antivirus-for-Windowshttps://support.avira.com/hc/en-us/articles/360000109798-Avira-Antivirus-for-Windowshttp://web.archive.org/web/20200429193852/https://support.avira.com/hc/en-us/articles/360000109798-Avira-Antivirus-for-Windowshttps://support.avira.com/hc/en-us/articles/360000109798-Avira-Antivirus-for-Windows
2020-04-26
Published