Heap Buffer Out-of-Bounds Read in Avast Antivirus and Related Products
CVE-2025-7009

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7009?

A heap buffer out-of-bounds read vulnerability exists in Avast Antivirus that affects the scanning of malformed Windows PE files. This flaw may allow for local execution of code or cause a denial-of-service condition in the antivirus process. The issue impacts multiple antivirus products from Gen Digital, including Avast, AVG, and Norton, on various platforms such as Windows, macOS, and Linux if they utilize virus definition builds prior to VPS 25021310. Proper mitigation requires updates through the shared Gen Digital virus definition stream to ensure installations are secure.

Affected Version(s)

Avast Antivirus Windows 0

Avast Business Antivirus Windows 0

Avast One Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.