WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attackers can leverage the overly permissive access controls to potentially modify critical DLLs and executable files in the WinAVR installation directory.
Exploitability
AV:LAC:LAT:NPR:LUI:AVulnerable System
VC:HVI:HVA:HSubsequent System
SC:NSI:NSA:N7/CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NConfiguration