Junglewise Threat Intelligence

CVE-2025-7019: Gen Digital Antivirus stack overflow in Office Open XML scanning

CVE-2025-7019 · Severity: medium · CVSS 5.5 · Published 2026-06-12

Technologies: Gen Digital Avast Antivirus, Avast One, Gen Digital Norton Antivirus, Avast Business Antivirus, Gen Digital AVG Antivirus, Gen Digital Avast One, Gen Digital Avast Business Antivirus. Vendors: Gen Digital, Avast.

Executive brief

A vulnerability in several popular antivirus products, including Avast, AVG, and Norton, could allow a malicious file to crash the security software. By tricking a user into opening or downloading a specially crafted Office document, an attacker can cause the antivirus engine to stop functioning. This results in a denial-of-service, leaving the system temporarily unprotected against other threats.

Technical details

A stack-based buffer overflow (CWE-121) exists in the shared Gen Digital scanning logic used across multiple antivirus brands. The vulnerability is triggered when the engine attempts to parse a malformed Office Open XML (.docx, .xlsx, etc.) file. An attacker can exploit this by providing a specially crafted file that, when scanned, causes the antivirus process to crash (Denial-of-Service). The attack requires local access or user interaction (e.g., downloading the file). The fix is delivered via the virus definition update stream; systems are protected once they reach VPS build 25020100 or higher.

Affected products

  • Gen Digital Avast Antivirus Virus definition builds before VPS 25020100
  • Gen Digital AVG Antivirus Virus definition builds before VPS 25020100
  • Gen Digital Norton Antivirus Virus definition builds before VPS 25020100
  • Gen Digital Avast One Virus definition builds before VPS 25020100
  • Gen Digital Avast Business Antivirus Virus definition builds before VPS 25020100

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References

Related threats