Executive brief
Avira Antivirus is a security suite used to protect computers from malware and cyber threats. A vulnerability in its scanning engine could allow a local user to crash the antivirus service or potentially execute unauthorized code by tricking the software into scanning a specially crafted Windows installer (MSI) file. This could lead to a loss of system protection or unauthorized access to the device.
Technical details
A heap-based out-of-bounds read vulnerability (CWE-125) exists in the Avira Antivirus engine across Windows, macOS, and Linux platforms. The flaw is triggered when the engine processes a malformed Windows Installer (MSI) file during a scan. An attacker can exploit this by placing a crafted MSI file on a system where it will be scanned by the engine, potentially leading to a crash of the antivirus process (Denial of Service) or the execution of arbitrary code in the context of the engine. The vulnerability is addressed in engine builds 8.3.70.56 and later. Exploitation requires local access and user interaction (triggering a scan of the malicious file).
Affected products
- Avira Antivirus engine before 8.3.70.56
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory