Executive brief
A vulnerability exists in several popular antivirus products, including Avast, AVG, and Norton, which are used to protect computers from malware. If a user attempts to scan a specially crafted, malicious Windows file, the antivirus software could crash or allow an attacker to run unauthorized code on the system. This could lead to a complete compromise of the device or a disruption of security services.
Technical details
A heap buffer out-of-bounds read (CWE-125) exists in the shared scanning logic of Gen Digital antivirus products. The vulnerability is triggered when the engine processes a malformed Windows Portable Executable (PE) file. While the attack vector is classified as local, it requires user interaction (UI:R), such as a user or a scheduled task initiating a scan of the malicious file. Successful exploitation can lead to a denial-of-service (DoS) of the antivirus process or potentially arbitrary code execution. The flaw resides in the virus definition update stream (VPS) rather than the main application binaries. A fix has been released via the shared update channel; all installations with virus definition build VPS 25021310 or later are protected.
Affected products
- Gen Digital Avast Antivirus before VPS 25021310
- Gen Digital AVG Antivirus before VPS 25021310
- Gen Digital Norton Antivirus before VPS 25021310
- Gen Digital Avast One before VPS 25021310
- Gen Digital Avast Business Antivirus before VPS 25021310
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2025-02-13: patched: Fix released in VPS build 25021310