Heap Buffer Out-of-Bounds Read Vulnerability in Avira Antivirus Software
CVE-2025-9033

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2025-9033?

A heap buffer out-of-bounds read vulnerability exists within the Avira Antivirus engine, particularly when handling malformed PDF files. This issue may lead to potential local execution of code or cause a Denial-of-Service condition, severely impacting the antivirus engine's functionality. The vulnerability affects all builds prior to version 8.3.70.76 on Windows, macOS, and Linux platforms, thereby highlighting the importance of immediate updates to maintain optimal security.

Affected Version(s)

Avira Antivirus Windows 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Zhang, an independent security researcher
.