Uncontrolled Recursion Vulnerability in Avast Antivirus and Other Gen Digital Products
CVE-2025-7005

5.5MEDIUM

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7005?

An uncontrolled recursion vulnerability exists in Avast Antivirus and other related Gen Digital products, triggered during the scanning of malformed Windows PE files. This could potentially lead to a Denial-of-Service condition affecting the antivirus process across various platforms, including Windows, macOS, and Linux. The issue affects specific versions using the shared virus definition update stream, but installations with updates at or above VPS 25031700 are not susceptible to this vulnerability. Users are advised to ensure their antivirus products are updated to avoid risks associated with this issue.

Affected Version(s)

Avast Antivirus Windows 0

Avast Business Antivirus Windows 0

Avast One Windows 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.