No, Avast is not vulnerable.
Thanks Polunus for bringing this possible issue.
“From the security perspective, we are OK, as restore is done under user account who requested it, so no privilege escalation is possible”.
“And about the statement about weakening HTTPs security mentioned at the end of the article, I guess we have answered here: https://blog.avast.com/avasts-https-scanner-receives-a-rating”
(from Virus Lab)