Heap Buffer Out-of-Bounds Vulnerability in Avast Antivirus Suite
CVE-2025-7008
7.8HIGH
What is CVE-2025-7008?
A heap buffer out-of-bounds read vulnerability exists in Avast Antivirus, which can occur when scanning specifically crafted Windows PE files containing .NET metadata. This flaw may enable local execution of arbitrary code or result in a denial-of-service condition affecting the antivirus process. The shared Gen Digital virus definition update stream delivers this problematic scanning logic, impacting a range of antivirus products by Gen Digital. Security updates addressing this issue are included in virus definition builds at or above VPS 25021310, which mitigates the vulnerability regardless of the consuming product.
Affected Version(s)
Avast Antivirus Windows 0
Avast Business Antivirus Windows 0
Avast One Windows 0
