Avira, three security vulnerabilities in security software

Three high-risk security vulnerabilities in Avira's security software allow attackers to run code with system privileges... among other things.

Researchers have discovered security flaws in Avira anti-malware software that could allow attackers to compromise vulnerable systems. In some cases, all they need to do is place certain files in specific user-accessible locations on the file system. This alone allows arbitrary code to be executed with system privileges.

See more articles from iGuRu.gr when you search for news on Google.

Specifically, Quarkslab analysts discovered the vulnerabilities in the freeware “Avira Free Security” and Avira Internet Security. In all cases, attackers can use a technique that allows them to execute code by deleting specific files through the security software. Trend Micro’s Zero-Day Initiative (ZDI) provides us with a comprehensive report of the vulnerabilities in Avira software.

The software updater does not have any check to determine whether a file in “C:\ProgramData” is a symbolic link.

Attackers can therefore create a malicious symbolic link to delete arbitrary files on the system with “SYSTEM” permissions. This allows for privilege escalation and a complete system compromise ( CVE-2026-27748 , CVSS4 8.5, High severity).

The System Speedup component, on the other hand, deserializes data from a file in the aforementioned folder without any checks or security measures. By default, local users can create or modify this file. Attackers can exploit this directly locally or, for example, through social engineering over the network against unsuspecting victims to run arbitrary code with “SYSTEM” privileges ( CVE-2026-27749 , CVSS4 8.5, High severity).

The third vulnerability affects Avira's Optimizer service and is time-based: a file is checked but can still be modified before use (check-time-of-use, TOCTOU). The service scans with permissions which folders can be deleted for system cleanup and then deletes them in a second pass. Attackers can replace an already scanned directory with a link or a so-called retry point and thus trick the service into deleting arbitrary files or folders with known consequences ( CVE-2026-27750 , CVSS4 8.5, High severity).


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).