CVE-2022-3368
Software Updater of Avira Security for Windows vulnerable to Privilege Escalation
- Published
- Oct 17, 2022
- Updated
- May 10, 2025
- Assigning CNA
- NLOK
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 57.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.
Sources
2- CrackAVFeeExploit
it's a CVE-2022-3368 (Patched), but feel free to use it for check any outdated software or reseach
Proof-of-concept for local privilege escalation in Avira Security via arbitrary file move, exploiting junction points to load a malicious DLL into a privileged service.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.