Heap Buffer Out-of-Bounds Write Vulnerability in Avira Antivirus
CVE-2025-14098

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-14098?

A vulnerability exists in the Avira Antivirus engine due to an integer overflow that may lead to a heap buffer out-of-bounds write. This issue arises when the antivirus scans a specially crafted MS-DOS executable file. As a result, it could potentially allow local execution of malicious code or trigger a denial-of-service condition, affecting the stability and security of the antivirus engine. This vulnerability impacts various platform builds prior to version 8.3.70.104.

Affected Version(s)

Avira Antivirus Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.