CVE-2026-27749PoC(avira / internet_security)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input validation or deserialization safeguards. Because the file can be created or modified by a local user in default configurations, an attacker can supply a crafted serialized payload that is deserialized by the privileged process, resulting in arbitrary code execution as SYSTEM.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_security

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-03); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
internet_security

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-04: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 103-0303-0403-0503-06
Signal classification2 categories
PoC
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-031
PoC1
2026-03-041
PoC1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
Full discourse4 posts
  • quarkslab@quarkslab
    PoC

    Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. 3 LPE vectors via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749). Find out more: https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html https://t.co/aipOEFZqnE

    Post summary

    The post announces privilege‑elevation exploits in Avira, citing CVE IDs and linking to a blog that presumably contains a PoC, but it does not mention active exploitation or patch availability.

    3381132449.3K
    12.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Gen Digital Avira Internet Security (CVE-2026-27749) https://vuldb.com/?id.349196

    Post summary

    The text announces a newly identified high‑criticality vulnerability (CVE-2026-27749) in Gen Digital Avira Internet Security, but provides no further technical details, exploitation evidence, or mitigation information.

    0000089
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27749 Avira System Speedup Deserialization Vulnerability Enables Arbitrary Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27749

    Post summary

    The post announces CVE-2026-27749, identifying it as a deserialization flaw that allows arbitrary code execution, but offers no PoC, patches, or details of active exploitation.

    0000027
    4.0K followersView on X
  • Autumn Good@autumn_good_35
    PoC

    CVE-2026-27748: Arbitrary file delete CVE-2026-27749: LPE via insecure deserialization CVE-2026-27750: LPE via TOCTOU folder delete Avira: Deserialize, Delete and Escalate - The Proper Way to Use an AV - Quarkslab's blog https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html

    Post summary

    The blog post outlines three Avira CVEs involving arbitrary file deletion and local privilege escalation via insecure deserialization and TOCTOU folder delete, and provides a proof‑of‑concept demonstration.

    00000356
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appavirainternet_security-windows-

Explore more