Executive brief
Avira Antivirus is a security suite used to protect computers from malware across Windows, macOS, and Linux. A vulnerability in its scanning engine could allow a malicious file to crash the antivirus service or potentially execute unauthorized code when the software attempts to scan it. This could lead to a loss of system protection or allow an attacker to gain deeper access to the affected machine.
Technical details
A heap-based buffer out-of-bounds write vulnerability exists in the Avira Antivirus engine due to an integer overflow (CWE-190) triggered during the parsing of malformed MS-DOS executable files. The flaw resides in the engine's file scanning component across Windows, macOS, and Linux platforms. An attacker can exploit this by providing a specially crafted executable that, when scanned, causes an out-of-bounds write (CWE-787). Successful exploitation requires user interaction (e.g., downloading or opening a folder containing the file) and can result in local code execution or a denial-of-service (DoS) of the antivirus process. The issue is resolved in engine builds 8.3.70.104 and later.
Affected products
- Avira Antivirus engine before 8.3.70.104
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory