Vulnerability Details CVE-2018-12572
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 2.1
Products affected by CVE-2018-12572
-
cpe:2.3:a:avast:free_antivirus:11.1.2241
-
cpe:2.3:a:avast:free_antivirus:11.1.2245
-
cpe:2.3:a:avast:free_antivirus:11.1.2253
-
cpe:2.3:a:avast:free_antivirus:11.1.2260
-
cpe:2.3:a:avast:free_antivirus:11.1.2261
-
cpe:2.3:a:avast:free_antivirus:11.1.2262
-
cpe:2.3:a:avast:free_antivirus:12.1.2272
-
cpe:2.3:a:avast:free_antivirus:12.2.2276
-
cpe:2.3:a:avast:free_antivirus:12.3
-
cpe:2.3:a:avast:free_antivirus:12.3.2279
-
cpe:2.3:a:avast:free_antivirus:17.1.2286
-
cpe:2.3:a:avast:free_antivirus:17.2.2288
-
cpe:2.3:a:avast:free_antivirus:17.3.2290
-
cpe:2.3:a:avast:free_antivirus:17.3.2291
-
cpe:2.3:a:avast:free_antivirus:17.4.2294
-
cpe:2.3:a:avast:free_antivirus:17.5.2302
-
cpe:2.3:a:avast:free_antivirus:17.6.2310
-
cpe:2.3:a:avast:free_antivirus:17.7.2314
-
cpe:2.3:a:avast:free_antivirus:17.8.2318
-
cpe:2.3:a:avast:free_antivirus:17.9.2322
-
cpe:2.3:a:avast:free_antivirus:18.1.2326
-
cpe:2.3:a:avast:free_antivirus:18.2.2328
-
cpe:2.3:a:avast:free_antivirus:18.3.2333
-
cpe:2.3:a:avast:free_antivirus:18.4.2338
-
cpe:2.3:a:avast:free_antivirus:18.5.2342
-
cpe:2.3:a:avast:free_antivirus:18.6.2349
-
cpe:2.3:a:avast:free_antivirus:18.7.2354
-
cpe:2.3:a:avast:free_antivirus:18.8.2356