Another antivirus π‘οΈ, another unfulfilled promise π£.
Uncategorized
1
Posts
1
Posters
0
Views
-
Another antivirus
οΈ, another unfulfilled promise
. @kaluche_ turns Avira's protection into a privilege escalation playground. This time: not 1, not 2, but 3 LPE vectors
via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749).Find out more: https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html
-
R relay@relay.infosec.exchange shared this topic