CVE-2026-27750
7.8Gen Digital Inc. · Avira Internet Security
Avira Internet Security contains a TOCTOU race condition in the Optimizer component, allowing a local attacker to perform arbitrary file deletion and potential privilege escalation.
Executive summary
A time-of-check time-of-use vulnerability in the Avira Internet Security Optimizer component exposes systems to local privilege escalation and unauthorized file deletion.
Vulnerability
This is a race condition (CWE-367) where a privileged service performs cleanup tasks without revalidating target paths between the scan and deletion phases. A local attacker with low privileges can exploit this gap to trick the system into deleting sensitive files.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk due to the potential for total system compromise. Successful exploitation allows a local attacker to delete critical system files, leading to denial of service or the elevation of privileges to SYSTEM level, which could result in full loss of system integrity and confidentiality.
Remediation
Immediate Action: Upgrade Avira Internet Security for Windows to version 1.1.114.3113 or later via the built-in updater or a fresh installation.
Proactive Monitoring: Review system logs for unusual file deletion activity or unexpected creation of junction points and reparse points within protected directories.
Compensating Controls: Restrict local user permissions where possible to limit the ability of non-administrative users to interact with directory structures targeted by the Optimizer service.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for full system compromise, administrators must prioritize updating Avira Internet Security to version 1.1.114.3113 or higher. The existence of a proof-of-concept elevates the urgency of this patch, and failure to remediate could allow local attackers to gain unauthorized control over affected systems.