Junglewise Threat Intelligence

CVE-2025-7002: Avira Antivirus heap out-of-bounds read in PDF scanning engine

CVE-2025-7002 · Severity: high · CVSS 7.8 · Published 2026-06-12

Vendors: Avira.

Executive brief

Avira Antivirus is a security suite used to protect Windows, macOS, and Linux systems from malware. A vulnerability in the software's scanning engine could allow an attacker to crash the security service or potentially execute unauthorized code if the user is tricked into scanning a specially crafted PDF file. This could lead to a loss of system protection or a full compromise of the affected computer.

Technical details

A heap-based out-of-bounds read vulnerability exists in the Avira Antivirus engine (versions prior to 8.3.70.68) across Windows, macOS, and Linux platforms. The flaw is triggered when the engine parses a malformed PDF file during a scan operation. While primarily an out-of-bounds read, the advisory indicates this can be leveraged for either a Denial-of-Service (DoS) of the antivirus process or Local Code Execution (LCE). Exploitation requires a user to interact with a malicious file (UI:R), such as by downloading or opening a directory containing the malformed PDF that triggers an automatic scan. The issue is addressed in engine build 8.3.70.68 and later.

Affected products

  • Avira Antivirus engine builds before 8.3.70.68

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References