CVE-2020-9320 Information

Description

Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint Antivirus for Small Business Exchange Security (Gateway) Internet Security Suite for Windows Prime Free Security Suite for Windows and Cross Platform Anti-malware SDK.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

http://packetstormsecurity.com/files/156472/AVIRA-Generic-Malformed-Container-Bypass.html http://seclists.org/fulldisclosure/2020/Feb/31 https://blog.zoller.lu/p/from-low-hanging-fruit-department-avira.html https://www.zoller.lu/[TZO-01-2020]20AVIRA20Generic20Bypass20ISO.pdf

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

5.5

Share on: