Junglewise Threat Intelligence

CVE-2025-7009: Gen Digital Antivirus out-of-bounds read in PE file scanning

CVE-2025-7009 · Severity: high · CVSS 7.8 · Published 2026-06-12

Technologies: Gen Digital Avast Antivirus, Gen Digital Avast Business Antivirus, Gen Digital AVG Antivirus, Gen Digital Norton Antivirus, Gen Digital Avast One. Vendors: Gen Digital.

Executive brief

A vulnerability exists in several popular antivirus products, including Avast, AVG, and Norton, which are used to protect computers from malware. If a user attempts to scan a specially crafted, malicious Windows file, the antivirus software could crash or allow an attacker to run unauthorized code on the system. This could lead to a complete compromise of the device or a disruption of security services.

Technical details

A heap buffer out-of-bounds read (CWE-125) exists in the shared scanning logic of Gen Digital antivirus products. The vulnerability is triggered when the engine processes a malformed Windows Portable Executable (PE) file. While the attack vector is classified as local, it requires user interaction (UI:R), such as a user or a scheduled task initiating a scan of the malicious file. Successful exploitation can lead to a denial-of-service (DoS) of the antivirus process or potentially arbitrary code execution. The flaw resides in the virus definition update stream (VPS) rather than the main application binaries. A fix has been released via the shared update channel; all installations with virus definition build VPS 25021310 or later are protected.

Affected products

  • Gen Digital Avast Antivirus before VPS 25021310
  • Gen Digital AVG Antivirus before VPS 25021310
  • Gen Digital Norton Antivirus before VPS 25021310
  • Gen Digital Avast One before VPS 25021310
  • Gen Digital Avast Business Antivirus before VPS 25021310

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2025-02-13: patched: Fix released in VPS build 25021310

References

Related threats