Stack Overflow Vulnerability in Avast Antivirus and Related Products
CVE-2025-7010

5.5MEDIUM

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7010?

A stack overflow vulnerability has been identified in Avast Antivirus and related products, stemming from uncontrolled recursion during the scanning of malformed PDF files. This could potentially lead to a Denial-of-Service condition, impacting the antivirus process. The vulnerability affects several products from Gen Digital, including AVG Antivirus, Norton Antivirus, and others, across Windows, macOS, and Linux platforms. Users utilizing virus definition builds prior to VPS 25021208 are at risk. To mitigate this issue, users should ensure they are on the latest updates via the shared Gen Digital update stream, which provides essential fixes to prevent exploitation.

Affected Version(s)

Avast Antivirus Windows 0

Avast Business Antivirus Windows 0

Avast One Windows 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.