A public exploit turns Avast's own sandbox into a SYSTEM shell for any standard Windows user, and no patch exists; separately, Zimbra servers running an optional SNMP package are being compromised through SMTP input that becomes a shell command.
2 priority