Executive brief
A vulnerability in the scanning engine used by Avast, AVG, and Norton antivirus products could allow a specially crafted PDF file to crash the security software. This occurs when the antivirus attempts to scan a malformed file, leading to a 'Denial-of-Service' where the protection process stops functioning. While this does not directly expose data, it can leave the system unprotected against other threats until the service is restarted or the file is removed.
Technical details
A stack overflow vulnerability exists in the shared Gen Digital scanning engine due to uncontrolled recursion (CWE-674). The issue is triggered when the antivirus engine parses a specifically malformed PDF file during a scan. An attacker can exploit this by providing a crafted PDF to the system, which, when scanned, causes the antivirus process to crash (Denial-of-Service). The vulnerability is present in the virus definition (VPS) stream rather than the core application binaries. It affects multiple product lines across Windows, macOS, and Linux. A fix has been released via the automated virus definition update channel in VPS build 25021208.
Affected products
- Gen Digital Avast Antivirus VPS builds before 25021208
- Gen Digital AVG Antivirus VPS builds before 25021208
- Gen Digital Norton Antivirus VPS builds before 25021208
- Gen Digital Avast One VPS builds before 25021208
- Gen Digital Avast Business Antivirus VPS builds before 25021208
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2025-02-12: patched: Fixed in VPS build 25021208