Null Pointer Dereference in Avira Antivirus on Multiple Platforms
CVE-2025-7018

5.5MEDIUM

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-7018?

A null pointer dereference vulnerability exists within the Avira Antivirus engine when it attempts to scan a malformed Windows PE file. This flaw may lead to a Denial-of-Service condition, causing the antivirus engine to crash and become unresponsive. Affected versions prior to 8.3.70.64 on Windows, macOS, and Linux are particularly at risk. Keeping the software updated is essential to mitigate this vulnerability.

Affected Version(s)

Avira Antivirus Windows 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.