Heap Buffer Vulnerability in Avira Antivirus Software
CVE-2025-9032

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-9032?

A heap buffer out-of-bounds read vulnerability exists in the Avira Antivirus engine, which may be triggered when an improperly formatted Windows PE file is scanned. This flaw potentially enables local code execution or causes a Denial-of-Service condition affecting the antivirus engine's stability. The vulnerability affects various platforms including Windows, macOS, and Linux for engine builds prior to version 8.3.70.98.

Affected Version(s)

Avira Antivirus Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.