The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

vulnerability alert CVE-2015-8620

Avast Antivirus: buffer overflow of aswSnx.sys

Synthesis of the vulnerability

An attacker can generate a buffer overflow in aswSnx.sys of Avast, in order to trigger a denial of service, and possibly to run code with system privileges.
Impacted products: Avast AV.
Severity: 2/4.
Creation date: 23/02/2016.
Revision date: 16/06/2017.
Identifiers: CVE-2015-8620, VIGILANCE-VUL-19011, ZDI-16-681.

Description of the vulnerability

The Avast product installs the aswSnx.sys (Avast Virtualization) driver.

However, if the size of data is greater than the size of the storage array, an overflow occurs in aswSnx.sys. Technical details are unknown.

An attacker can therefore generate a buffer overflow in aswSnx.sys of Avast, in order to trigger a denial of service, and possibly to run code with system privileges.
Complete Vigil@nce bulletin.... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides a software vulnerabilities database. The technology watch team tracks security threats targeting the computer system. The Vigil@nce vulnerability database contains several thousand vulnerabilities. Each administrator can customize the list of products for which he wants to receive vulnerability alerts.