CVE-2018-12572

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
21/03/2019
Last modified:
24/08/2020

Description

Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avast:free_antivirus:*:*:*:*:*:*:*:* 19.1.2360 (excluding)