Executive brief
A vulnerability exists in several popular antivirus products, including Avast, AVG, and Norton, which are used to protect computers from malware. If a user attempts to scan a specially crafted, malicious file, the antivirus software may crash and stop functioning. This results in a denial-of-service, leaving the system temporarily unprotected until the antivirus process is restarted.
Technical details
A 'Free of Memory not on the Heap' (CWE-590) vulnerability exists in the shared scanning logic used by Avast, AVG, and Norton antivirus products. The flaw is triggered when the engine attempts to scan a malformed Windows Portable Executable (PE) file, leading to a use-after-free condition involving stack memory. An attacker can exploit this by providing a crafted file to be scanned, causing the antivirus process to crash (Denial-of-Service). The vulnerability is local in nature but requires user interaction (e.g., downloading or opening a folder containing the file). The issue is resolved in virus definition builds VPS 25022500 and later.
Affected products
- Gen Digital (Avast) Avast Antivirus Virus definition builds before VPS 25022500
- Gen Digital (AVG) AVG Antivirus Virus definition builds before VPS 25022500
- Gen Digital (Norton) Norton Antivirus Virus definition builds before VPS 25022500
- Gen Digital (Avast) Avast One Virus definition builds before VPS 25022500
- Gen Digital (Avast) Avast Business Antivirus Virus definition builds before VPS 25022500
Timeline
- 2026-06-12: disclosed
- 2025-02-25: patched: Date inferred from VPS version string 25022500 (Feb 25, 2025)