Junglewise Threat Intelligence

CVE-2025-7008: Gen Digital Antivirus heap out-of-bounds read in .NET metadata scanning

CVE-2025-7008 · Severity: high · CVSS 7.8 · Published 2026-06-12

Technologies: Gen Digital Avast Antivirus, Gen Digital Avast Business Antivirus, Gen Digital AVG Antivirus, Gen Digital Norton Antivirus, Gen Digital Avast One. Vendors: Gen Digital.

Executive brief

A vulnerability in several popular antivirus products, including Norton, Avast, and AVG, could allow an attacker to crash the security software or potentially execute malicious code. This occurs when the antivirus engine scans a specially crafted Windows file containing malformed metadata. If exploited, this could disable the system's primary defense mechanism or allow an attacker to gain deeper control over the computer.

Technical details

A heap buffer out-of-bounds read vulnerability (CWE-125) exists in the shared scanning engine used by Gen Digital products, including Avast, AVG, and Norton. The flaw is triggered when the engine processes a malformed Windows Portable Executable (PE) file containing specifically crafted .NET metadata. While the attack vector is local, it requires minimal privileges but does necessitate user interaction (e.g., a user downloading or opening a folder containing the malicious file to trigger a scan). Successful exploitation can lead to a denial-of-service (DoS) by crashing the antivirus process or potentially achieving local code execution. The vulnerability was addressed via the virus definition update stream (VPS).

Affected products

  • Gen Digital Avast Antivirus before VPS 25021310
  • Gen Digital AVG Antivirus before VPS 25021310
  • Gen Digital Norton Antivirus before VPS 25021310
  • Gen Digital Avast One before VPS 25021310
  • Gen Digital Avast Business Antivirus before VPS 25021310

Timeline

  • 2026-06-12: disclosed: NVD publication date
  • 2025-02-13: patched: Fix released in VPS build 25021310

References

Related threats