PT-2026-49012 · Avast+2 · Avast Antivirus+4
CVE-2025-7006
·
Published
2026-06-12
·
Updated
2026-06-13
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Avast Antivirus versions prior to VPS 25022500
AVG Antivirus versions prior to VPS 25022500
Norton Antivirus versions prior to VPS 25022500
Avast One versions prior to VPS 25022500
Avast Business Antivirus versions prior to VPS 25022500
Description
A use-after-free vulnerability occurs in the stack memory when scanning a malformed Windows PE (Portable Executable) file, which is a file format used by Windows for executables, DLLs, and drivers. This flaw can lead to a Denial-of-Service of the antivirus process.
Recommendations
Update to virus definition build VPS 25022500 or later for all affected products.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avg Antivirus
Avast Antivirus
Avast Business Antivirus
Avast One
Norton Antivirus