CVE-2017-8308: Avast Antivirus

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product, opening a door to subsequent attack on many of its components.

Affected products

  • Avast Antivirus: up to and including 12.3.2279

Published 2017-04-27. Last modified 2026-06-17.