ZeroHour

CVE-2020-25289

PoC
CVSS 3.1
5.5 medium
EPSS
<1%p38
Published
()
Modified
Description

The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).

Vendors
avast
Products
secureline vpn
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.