Junglewise Threat Intelligence

CVE-2025-9033: Avira Antivirus heap out-of-bounds read in scanning engine

CVE-2025-9033 · Severity: high · CVSS 7.8 · Published 2026-06-12

Vendors: Avira.

Executive brief

Avira Antivirus is a security suite used to protect computers from malware and cyber threats. A vulnerability in its scanning engine could allow a malicious PDF file to crash the antivirus software or potentially allow an attacker to run unauthorized code on the system. This occurs when the software attempts to scan a specially crafted file, potentially leading to a loss of protection or system compromise.

Technical details

A heap buffer out-of-bounds read vulnerability exists in the Avira Antivirus engine across Windows, macOS, and Linux platforms. The flaw is triggered when the engine processes a malformed PDF file during a scan. An attacker can exploit this by providing a specially crafted PDF, which, when parsed, causes the engine to read beyond the intended buffer boundaries. This can result in a denial-of-service (crashing the antivirus process) or potentially local execution of arbitrary code. The issue is resolved in engine builds 8.3.70.76 and later.

Affected products

  • Avira Antivirus engine builds before 8.3.70.76

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References