Junglewise Threat Intelligence

CVE-2025-9032: Avira Antivirus heap out-of-bounds read in scanning engine

CVE-2025-9032 · Severity: high · CVSS 7.8 · Published 2026-06-12

Technologies: Avira Antivirus Engine. Vendors: Avira.

Executive brief

Avira Antivirus is a security suite used to protect computers from malware and cyber threats. A vulnerability in its scanning engine could allow a malicious file to crash the software or potentially run unauthorized code on the system when the file is scanned. This could lead to a loss of protection or allow an attacker to gain control over the affected device.

Technical details

A heap buffer out-of-bounds read vulnerability exists in the Avira Antivirus engine across Windows, macOS, and Linux platforms. The flaw is triggered when the engine attempts to scan a specially crafted, malformed Windows Portable Executable (PE) file. An attacker can exploit this by inducing the engine to process such a file, which may result in a denial-of-service (crashing the antivirus process) or arbitrary code execution in the context of the scanning engine. The vulnerability is addressed in engine builds 8.3.70.98 and later.

Affected products

  • Avira Antivirus engine before 8.3.70.98

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References

Related threats