
Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. 3 LPE vectors via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749). Find out more: https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html https://t.co/aipOEFZqnE
Post summary
Quarkslab’s blog post discloses three new Avira privilege‑escalation vulnerabilities involving symlink abuse and unsafe deserialization; no patches or active exploitation are reported, but technical details are provided.


