CVE-2024-9484

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Nov 8, 2024
CWE ID 476

Summary

CVE-2024-9484 is a null-pointer dereference vulnerability discovered in the engine module of AVG/Avast Antivirus for MacOS. This issue arises when processing a malformed xar file, leading to a crash of the application. An attacker can exploit this vulnerability by creating and deploying a specifically crafted xar file, potentially resulting in denial-of-service or gaining unauthorized access to the system. Users are recommended to update their antivirus software to the latest version, released on 24/Sep/2024, which includes a patch for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • AVG Antivirus
  • Avast Antivirus

Affected Vendors

  • AVG Technologies N.V.
  • Avast