Junglewise Threat Intelligence

CVE-2025-7004: Gen Digital Antivirus heap overflow in Windows PE scanning

CVE-2025-7004 · Severity: high · CVSS 7.8 · Published 2026-06-12

Technologies: Gen Digital Avast Antivirus, Gen Digital Avast Business Antivirus, Gen Digital AVG Antivirus, Gen Digital Norton Antivirus, Gen Digital Avast One. Vendors: Gen Digital.

Executive brief

A vulnerability in several popular antivirus products, including Avast, AVG, and Norton, could allow an attacker to execute malicious code or crash the security software. This occurs when the antivirus engine scans a specially crafted Windows executable file. If exploited, an attacker could gain unauthorized control over the system or disable the antivirus protection entirely.

Technical details

A heap-based out-of-bounds write vulnerability exists in the Gen Digital scanning engine used across multiple antivirus brands. The flaw is triggered when the engine processes a malformed Windows Portable Executable (PE) file. While the attack vector is local, it requires minimal privileges (PR:N) but does require user interaction (UI:R), such as a user or the system attempting to scan the malicious file. Successful exploitation can lead to arbitrary code execution in the context of the antivirus process or a denial-of-service (DoS) by crashing the scanning service. The vulnerability was addressed via a virus definition update (VPS 25040308) rather than a full software version increment.

Affected products

  • Gen Digital Avast Antivirus Virus definition builds before VPS 25040308
  • Gen Digital AVG Antivirus Virus definition builds before VPS 25040308
  • Gen Digital Norton Antivirus Virus definition builds before VPS 25040308
  • Gen Digital Avast One Virus definition builds before VPS 25040308
  • Gen Digital Avast Business Antivirus Virus definition builds before VPS 25040308

Timeline

  • 2026-06-12: advisory: NVD publication date
  • 2025-04-03: patched: Estimated patch date based on VPS version string 25040308

References

Related threats