CVE-2022-4429Unquoted Search Path or Element in Security

Severity
4.4MEDIUMNVD
CNA5.3
EPSS
0.1%
top 66.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10

Description

Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service. The issue was fixed with Avira Security version 1.1.78

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5nortonlifelock/avira_security_for_windowsup to version 1.1.77
NVDavira/avira_security< 1.1.78

🔴Vulnerability Details

2
CVEList
Avira Security for Windows - Denial of Service2023-01-10
GHSA
GHSA-gxx5-7x36-j997: Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service2023-01-10
CVE-2022-4429 — Unquoted Search Path or Element | cvebase