CVE-2018-12572: Avast Free Antivirus

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.

Affected products

  • Avast Free Antivirus: before 19.1.2360 (fixed in 19.1.2360)

Published 2019-03-21. Last modified 2026-06-17.