Heap Out-of-Bounds Read Vulnerability in Gen Digital Antivirus Products
CVE-2025-7011

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7011?

A heap out-of-bounds read vulnerability exists in Gen Digital antivirus products when they encounter a malformed zip file with XML. This vulnerability could potentially lead to local execution of code or a denial-of-service condition affecting the antivirus process. The flaw impacts various antivirus offerings from Gen Digital on multiple operating systems, including Windows, macOS, and Linux, for specific virus definition builds. Mitigation is available via an update channel that ensures installations at or above the specified build are protected.

Affected Version(s)

Avast Antivirus Windows 25020100

Avast Business Antivirus Windows 25020100

Avast One Windows 25020100

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.