PT-2026-49010 · Avast+2 · Avast Antivirus+4
CVE-2025-7004
·
Published
2026-06-12
·
Updated
2026-06-13
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avast Antivirus versions prior to VPS 25040308
AVG Antivirus versions prior to VPS 25040308
Norton Antivirus versions prior to VPS 25040308
Avast One versions prior to VPS 25040308
Avast Business Antivirus versions prior to VPS 25040308
Description
A heap buffer out-of-bounds write occurs when scanning a malformed Windows PE file. This issue can lead to local execution of code or a denial-of-service of the antivirus process. The flaw exists within the scanning logic delivered via a shared Gen Digital virus definition update stream used across multiple products on Windows, macOS, and Linux.
Recommendations
Update to virus definition build VPS 25040308 or later for all affected products.
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avg Antivirus
Avast Antivirus
Avast Business Antivirus
Avast One
Norton Antivirus