CVE-2020-25289

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
13/09/2020
Last modified:
17/09/2020

Description

The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avast:secureline_vpn:*:*:*:*:*:*:*:* 5.6.4982.470 (excluding)