Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
History

Fri, 09 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 May 2025 15:30:00 +0000

Type Values Removed Values Added
Description Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
Title Avast Cleanup Premium TuneupSvc Link Following Local Privilege Escalation Vulnerability
Weaknesses CWE-367
CWE-59
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NLOK

Published: 2025-05-09T15:20:42.493Z

Updated: 2025-05-09T17:38:53.172Z

Reserved: 2025-05-09T14:44:31.333Z

Link: CVE-2024-13961

cve-icon Vulnrichment

Updated: 2025-05-09T17:22:57.379Z

cve-icon NVD

Status : Received

Published: 2025-05-09T16:15:23.583

Modified: 2025-05-09T16:15:23.583

Link: CVE-2024-13961

cve-icon Redhat

No data.