Executive brief
Avira Antivirus is a security suite used to protect computers from malware and cyber threats. A vulnerability in its scanning engine could allow a specially crafted file to crash the antivirus software when it is scanned. This results in a denial-of-service, leaving the system temporarily unprotected until the antivirus process is restarted.
Technical details
A NULL pointer dereference (CWE-476) exists in the Avira Antivirus engine across Windows, macOS, and Linux platforms. The vulnerability is triggered when the engine attempts to parse a malformed Windows Portable Executable (PE) file during a scan. An attacker can exploit this by providing a crafted PE file that, when processed, causes the antivirus engine process to crash (Denial-of-Service). The attack requires the file to be scanned, typically involving some level of user interaction or automated system activity. The issue is resolved in engine builds 8.3.70.64 and later.
Affected products
- Avira Antivirus engine before 8.3.70.64
Timeline
- 2026-06-12: advisory: NVD publication date
- 2026-06-12: disclosed: Initial disclosure by NortonLifeLock Inc. (Gen Digital)