Impact
A malformed PDF file triggers a heap buffer out‑of‑bounds read in the Avira Antivirus engine, allowing a locally authenticated user to read memory beyond the buffer. This flaw can lead to the execution of arbitrary code or cause the antivirus engine process to crash, resulting in denial of service. The vulnerability falls under CWE‑125.
Affected Systems
Gen Digital Avira Antivirus on Windows, macOS, and Linux, specifically engine builds older than 8.3.70.68, are affected.
Risk and Exploitability
The CVSS score of 7.8 signals high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Because the attack requires local execution and potentially local user access, the opportunity for exploitation may be limited to environments where a user can run the scanner, but once achieved, the attacker could elevate privileges or crash the antivirus process.
OpenCVE Enrichment