CVE-2017-5567 Details
Description
Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Avast process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://cybellum.com/doubleagent-taking-full-control-antivirus/ | CVE | Third Party Advisory |
| http://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/ | CVE | Technical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/97017 | CVE | Third Party AdvisoryVDB Entry |
| http://cybellum.com/doubleagent-taking-full-control-antivirus/ | [email protected] | Third Party Advisory |
| http://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/ | [email protected] | Technical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/97017 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| avast free antivirus | <= 12.3 |
CPE
Remediation
| |
| avast internet security | <= 12.3 |
CPE
Remediation
| |
| avast premier | <= 12.3 |
CPE
Remediation
| |
| avast pro antivirus | <= 12.3 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Mar 30, 2017 | Initial Analysis | [email protected] |
| Mar 24, 2017 | CVE Modified | [email protected] |