« Volver al listado

CVE-2022-4294

Estado: ModificadaAlta (7.8)—

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-4294",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-4294",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-08T14:53:38.976759Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@nortonlifelock.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@nortonlifelock.com",
      "affectedData": [
        {
          "vendor": "NortonLifelock (GenDigital)",
          "product": "Norton Antivirus Windows Eraser Engine",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 119.1.5.1"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NortonLifelock (GenDigital)",
          "product": "Avira Security ",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 1.1.78"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NortonLifelock (GenDigital)",
          "product": "Avast Antivirus",
          "versions": [
            {
              "status": "affected",
              "version": "Prior to 22.10"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NortonLifelock (GenDigital)",
          "product": "AVG Antivirus",
          "versions": [
            {
              "status": "affected",
              "version": "Prior to 22.10"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-01-10T10:15:12.933",
  "references": [
    {
      "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@nortonlifelock.com"
    },
    {
      "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@nortonlifelock.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.\n"
    },
    {
      "lang": "es",
      "value": "Norton, Avira, Avast y AVG Antivirus para Windows pueden ser susceptibles a una vulnerabilidad de escalada de privilegios, que es un tipo de problema por el cual un atacante puede intentar comprometer la aplicación de software para obtener acceso elevado a recursos que normalmente están protegidos de una aplicación o usuario."
    }
  ],
  "lastModified": "2026-06-17T05:20:30.640",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:avira:avira_security:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE949420-907D-4EBC-945B-A3EBEEC08532",
              "versionEndExcluding": "1.1.78"
            },
            {
              "criteria": "cpe:2.3:a:norton:power_eraser:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7703323C-C9D2-4338-864A-1AA2F99821FA",
              "versionEndExcluding": "119.1.5.1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22365077-58F2-4607-8EB8-79CDDF74348D",
              "versionEndExcluding": "22.10"
            },
            {
              "criteria": "cpe:2.3:a:avg:antivirus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AADAEC20-387E-4CF4-B0A5-DE5C9092C37A",
              "versionEndExcluding": "22.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@nortonlifelock.com"
}