Executive brief
A vulnerability in several popular antivirus products, including Norton, Avast, and AVG, could allow an attacker to crash the antivirus software. By tricking the system into scanning a specially crafted Windows file, the antivirus engine enters an infinite loop that exhausts system resources. This results in a denial-of-service, leaving the computer unprotected against other threats until the service is restored.
Technical details
An uncontrolled recursion vulnerability (CWE-674) exists in the scanning logic of the Gen Digital antivirus engine. The flaw is triggered when the engine attempts to parse a malformed Windows Portable Executable (PE) file. An attacker can exploit this by providing a crafted file that causes the scanning process to exhaust its stack or resources through recursive calls, leading to a crash of the antivirus service (Denial-of-Service). The vulnerability is platform-independent, affecting Windows, macOS, and Linux installations. It has been mitigated via a virus definition (VPS) update; all products using VPS build 25031700 or later are protected.
Affected products
- Gen Digital Avast Antivirus VPS builds before 25031700
- Gen Digital AVG Antivirus VPS builds before 25031700
- Gen Digital Norton Antivirus VPS builds before 25031700
- Gen Digital Avast One VPS builds before 25031700
- Gen Digital Avast Business Antivirus VPS builds before 25031700
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2025-03-17: patched: Date inferred from VPS version string 25031700