CVE-2015-8620: Avast Free Antivirus

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request.

Affected products

  • Avast Avast Free Antivirus: up to and including 11.1.2245
  • Avast Avast Internet Security: up to and including 11.1.2245
  • Avast Avast Premier: up to and including 11.1.2245
  • Avast Avast Pro Antivirus: up to and including 11.1.2245

Published 2016-04-13. Last modified 2026-06-17.