Heap Buffer Out-of-Bounds Read Vulnerability in Avira Antivirus Engine
CVE-2025-7017

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7017?

A heap buffer out-of-bounds read vulnerability exists in the Avira Antivirus engine, triggered when scanning a specially crafted malformed Windows MSI file. This flaw could be exploited to execute local code or potentially lead to a denial-of-service condition, affecting the stability and security of the antivirus process. Users on Windows, macOS, and Linux with engine builds prior to version 8.3.70.56 are particularly susceptible to this issue, necessitating prompt updates to protect against potential exploits.

Affected Version(s)

Avira Antivirus Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.