CVE-2019-17449

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
10/10/2019
Last modified:
05/08/2024

Description

Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avira:software_updater:*:*:*:*:*:*:*:* 2.0.6.21094 (excluding)