A time-of-check to time-of-use (TOCTOU) bug in handling...
Low severity
Unreviewed
Published
Nov 8, 2023
to the GitHub Advisory Database
•
Updated Nov 8, 2023
Description
Published by the National Vulnerability Database
Nov 8, 2023
Published to the GitHub Advisory Database
Nov 8, 2023
Last updated
Nov 8, 2023
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.
References