Junglewise Threat Intelligence

CVE-2025-8351: Avira Antivirus heap buffer overflow in scanning engine

CVE-2025-8351 · Severity: high · CVSS 7.8 · Published 2025-12-01

Vendors: Avira.

Executive brief

A vulnerability in the Avira Antivirus engine could allow an attacker to crash the security software or execute unauthorized code on a computer. This occurs when the antivirus scans a specially crafted, malicious file. If exploited, this could lead to a complete system takeover or a loss of antivirus protection, leaving the device vulnerable to other threats.

Technical details

A heap-based buffer overflow and out-of-bounds read vulnerability exists in the Avira Antivirus engine across Windows, macOS, and Linux platforms. The flaw is triggered when the engine processes a malformed file during a scan. An attacker can exploit this by placing a crafted file on the local system and waiting for the antivirus to scan it (User Interaction required). Successful exploitation can lead to arbitrary code execution with the privileges of the antivirus process or a denial-of-service (DoS) by crashing the engine. The issue is resolved in engine builds 8.3.70.98 and later.

Affected products

  • Avira Antivirus Engine builds before 8.3.70.98

Timeline

  • 2025-12-01: disclosed
  • 2025-12-01: advisory

References