Heap Buffer Out-of-Bounds Vulnerability in Avast Antivirus Suite
CVE-2025-7008

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7008?

A heap buffer out-of-bounds read vulnerability exists in Avast Antivirus, which can occur when scanning specifically crafted Windows PE files containing .NET metadata. This flaw may enable local execution of arbitrary code or result in a denial-of-service condition affecting the antivirus process. The shared Gen Digital virus definition update stream delivers this problematic scanning logic, impacting a range of antivirus products by Gen Digital. Security updates addressing this issue are included in virus definition builds at or above VPS 25021310, which mitigates the vulnerability regardless of the consuming product.

Affected Version(s)

Avast Antivirus Windows 0

Avast Business Antivirus Windows 0

Avast One Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.