Use of Stack Memory After Free in Avast Antivirus Suite
CVE-2025-7006

5.5MEDIUM

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7006?

A vulnerability exists in Avast Antivirus that involves the use of stack memory after it has been freed. This flaw can be triggered during the scanning of a malformed Windows PE file, which may result in a Denial-of-Service condition affecting the antivirus process. The issue is present in various products by Gen Digital, impacting users across multiple operating systems, including Windows, macOS, and Linux. Users are encouraged to ensure their virus definitions are updated to VPS 25022500 or later to mitigate this risk.

Affected Version(s)

Avast Antivirus Windows 0

Avast Business Antivirus Windows 0

Avast One Windows 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.