PT-2026-49014 · Avast+2 · Avast Antivirus+4

CVE-2025-7009

·

Published

2026-06-12

·

Updated

2026-06-13

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avast Antivirus versions prior to VPS 25021310 AVG Antivirus versions prior to VPS 25021310 Norton Antivirus versions prior to VPS 25021310 Avast One versions prior to VPS 25021310 Avast Business Antivirus versions prior to VPS 25021310
Description A heap buffer out-of-bounds read occurs when scanning a malformed Windows PE file. This issue can lead to local execution of code or a denial-of-service of the antivirus process. The flaw exists within the shared Gen Digital virus definition update stream used across multiple products.
Recommendations Update to virus definition build VPS 25021310 or later for all affected products.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7009

Affected Products

Avg Antivirus
Avast Antivirus
Avast Business Antivirus
Avast One
Norton Antivirus