CVE-2026-27750Disclosure(avira / internet_security)

LOWCVSS 7.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local attacker can replace a previously scanned directory with a junction or reparse point before deletion occurs, causing the privileged process to delete an unintended system location. This may result in deletion of protected files or directories and can lead to local privilege escalation, denial of service, or system integrity compromise depending on the affected target.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_security

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
internet_security

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-04: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 103-0303-0403-05
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-031
Disclosure1
2026-03-041
PoC1
2026-03-051
Disclosure1
Full discourse3 posts
  • quarkslab@quarkslab
    Disclosure

    Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. 3 LPE vectors via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749). Find out more: https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html https://t.co/aipOEFZqnE

    Post summary

    Quarkslab’s blog post discloses three new Avira privilege‑escalation vulnerabilities involving symlink abuse and unsafe deserialization; no patches or active exploitation are reported, but technical details are provided.

    3381132449.3K
    12.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27750 Avira Internet Security Optimizer TOCTOU Vulnerability Enables Privileged File Deletion https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27750

    Post summary

    The post announces a new TOCTOU vulnerability (CVE-2026-27750) in Avira Internet Security Optimizer that could allow privileged file deletion, with no exploit, PoC, or mitigation details disclosed.

    0000037
    4.0K followersView on X
  • Autumn Good@autumn_good_35
    PoC

    CVE-2026-27748: Arbitrary file delete CVE-2026-27749: LPE via insecure deserialization CVE-2026-27750: LPE via TOCTOU folder delete Avira: Deserialize, Delete and Escalate - The Proper Way to Use an AV - Quarkslab's blog https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html

    Post summary

    The blog post discusses three Avira CVEs—arbitrary file deletion and two local privilege escalation vectors—providing proof‑of‑concept details for each.

    00000356
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appavirainternet_security-windows-

Explore more