Executive brief
Avira Antivirus is a security suite used to protect computers from malware and cyber threats. A vulnerability in its scanning engine could allow a malicious file to crash the antivirus software or potentially run unauthorized code on the system. This occurs when the software attempts to scan a specially crafted archive file, potentially leading to a loss of protection or full system compromise.
Technical details
A heap-based out-of-bounds write vulnerability (CWE-787) exists in the Avira Antivirus engine's handling of POSIX tar archives. The flaw is triggered when the engine parses a malformed archive during a scan, leading to memory corruption. While the attack vector is classified as local, it requires a user to interact with a malicious file (UI:R), such as downloading or opening a crafted tar archive that the engine then scans. Successful exploitation can result in the execution of arbitrary code with the privileges of the antivirus process or a denial-of-service (DoS) by crashing the engine. The issue is resolved in engine builds 8.3.27.12 and later across Windows, macOS, and Linux platforms.
Affected products
- Avira Antivirus Engine builds before 8.3.27.12
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory