CVE-2023-5760: Avast Avg Antivirus
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.
Affected products
- Avast Avg Antivirus: version 23.8 only
Published 2023-11-08. Last modified 2026-06-17.