Executive brief
A vulnerability exists in several popular antivirus products, including Avast, AVG, and Norton, which are used to protect computers from malware. If a user is tricked into opening or scanning a specially crafted ZIP file, the antivirus software could crash or potentially allow an attacker to run unauthorized code on the system. This issue affects users on Windows, macOS, and Linux who have not updated their virus definitions recently.
Technical details
A heap out-of-bounds read vulnerability (CWE-125) exists in the scanning logic shared across multiple Gen Digital antivirus products. The flaw is triggered when the engine scans a malformed ZIP file containing specific XML content. While the attack vector is local, it requires no special privileges (PR:N) but does require user interaction (UI:R), such as a user downloading or attempting to scan the malicious archive. Successful exploitation can lead to a denial-of-service (crashing the antivirus process) or potentially arbitrary code execution. The vulnerability was introduced in virus definition build 25020100 and is resolved in build 25021208 or later.
Affected products
- Gen Digital Avast Antivirus virus definition builds from 25020100 before 25021208
- Gen Digital AVG Antivirus virus definition builds from 25020100 before 25021208
- Gen Digital Norton Antivirus virus definition builds from 25020100 before 25021208
- Gen Digital Avast One virus definition builds from 25020100 before 25021208
- Gen Digital Avast Business Antivirus virus definition builds from 25020100 before 25021208
Timeline
- 2026-06-12: disclosed: NVD publication date
- 2025-02-12: patched: Fixed in virus definition build 25021208