Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.
CVE ID: CVE-2024-13962
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: Avast
Product: CleanUp Premium
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.82% (scored less or equal to compared to others)
EPSS Date: 2025-06-07 (when was this score calculated)