Executive brief
Avira Antivirus is a security suite used to protect Windows, macOS, and Linux systems from malware. A vulnerability in the scanning engine allows a specially crafted PDF file to crash the antivirus service or potentially allow unauthorized code execution. This could lead to a loss of protection on the affected device or allow an attacker to gain further control over the system if a user is tricked into opening or scanning the malicious file.
Technical details
A heap-based out-of-bounds read vulnerability (CWE-125) exists in the Avira Antivirus engine across Windows, macOS, and Linux platforms. The flaw is triggered during the parsing and scanning of malformed PDF documents. While the attack vector is classified as local, it requires a user to interact with a malicious file (UI:R), such as downloading or attempting to scan it. Successful exploitation can result in a denial-of-service (DoS) by crashing the antivirus engine process or potentially achieving local code execution. The issue is resolved in engine builds 8.3.70.56 and later.
Affected products
- Avira Antivirus engine builds before 8.3.70.56
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory