TuneUp and services in Avast, AVG, Avira, Norton expose security vulnerabilities

The products of the Avast, AVG, Avira and Norton brands from Gen Digital include services with security leaks.

listen Print view
Virus detected in front of servers

(Image: vectorfusionart/Shutterstock.com)

3 min. read

The virus protection software of the Avast, AVG, Avira and Norton brands from Gen Digital includes system optimization services and other components that contain vulnerabilities. Users of the affected software should check whether they have installed newer versions than those known to be vulnerable.

Gen Digital has not yet published an overview or its own vulnerability reports with further information. Over the weekend, however, the parent company published several CVE vulnerability entries naming vulnerable versions and components.

The individual reports name the following programs and components:

All but the last vulnerability are gaps through which attackers can extend their rights in the system due to unchecked consequences of shortcuts (Link Following). For most of the vulnerabilities, the description states that local attackers can execute arbitrary code in the SYSTEM context by creating a symbolic link and launching a "time-of-check time-of-use" attack. The last vulnerability listed, on the other hand, allows system rights to be obtained by deleting arbitrary files.

Videos by heise

Although most of the CVE entries mention Windows 10 as the context, it is not clear why the software should not be vulnerable on other Windows versions. As Gen Digital is not releasing any further information, users of the vulnerable software can only check whether the versions they have installed are already newer. If necessary, they should then initiate the update process – or, if possible, uninstall the system optimization components if the components are not being used anyway.

As a rule, only products from one provider are susceptible to a particular vulnerability. However, as there are several brands under the Gen Digital umbrella, most of which also use the same software base, some problems can then also occur across brand boundaries –. For example, with elements of the TuneUp software, as can apparently be observed at present.

(dmk)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.