CVE-2026-27748

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. A local attacker can create a malicious link to redirect the delete operation to an arbitrary file, resulting in deletion of attacker-chosen files with SYSTEM privileges. This may lead to local privilege escalation, denial of service, or system integrity compromise depending on the targeted file and operating system configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:avira:internet_security:*:*:*:*:*:windows:*:*

History

No history.

Information

Published : 2026-03-05 15:16

Updated : 2026-03-13 01:22


NVD link : CVE-2026-27748

Mitre link : CVE-2026-27748

CVE.ORG link : CVE-2026-27748


JSON object : View

Products Affected

avira

  • internet_security
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')