
image credit: adobe stock
According to SentinelOne, the two vulnerabilities, tracked as CVE-2022-26522 and CVE-2022-26523, impacted both Avast and AVG antiviruses — Avast acquired AVG in 2016 and the flaws affect a shared anti-rootkit driver.
The security holes were reported to Avast in December and they were patched in February with the release of version 22.1.
Both SentinelOne and Avast said they have not seen any attacks exploiting these vulnerabilities.