PT-2026-49016 · Avast+2 · Avast Antivirus+4
CVE-2025-7011
·
Published
2026-06-12
·
Updated
2026-06-13
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avast Antivirus versions 25020100 through 25021207
AVG Antivirus versions 25020100 through 25021207
Norton Antivirus versions 25020100 through 25021207
Avast One versions 25020100 through 25021207
Avast Business Antivirus versions 25020100 through 25021207
Description
A heap out-of-bounds read occurs when scanning a malformed zip file containing XML. This issue can lead to local execution of code or a denial-of-service of the antivirus process. The flaw exists within the shared Gen Digital virus definition update stream used across multiple products on Windows, macOS, and Linux.
Recommendations
Update to virus definition build 25021208 or later for Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus.
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avg Antivirus
Avast Antivirus
Avast Business Antivirus
Avast One
Norton Antivirus