#VU26541 Input validation error in Avast Antivirus - CVE-2020-10863
Published: April 2, 2020
Avast Antivirus
Avast Software s.r.o.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe). A remote attacker can trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine.