Impact
This vulnerability is a heap out‑of‑bounds read that occurs while the antivirus engine parses a malformed zip file containing XML. The read can expose memory contents that an attacker could misuse to trigger local code execution or crash the antivirus process, resulting in denial‑of‑service. The weakness maps to CWE‑125.
Affected Systems
The affected products are Gen Digital’s antivirus family: Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus. They run on Windows, macOS, and Linux. Vulnerable builds are virus‑definition releases from 25020100 up to, but not including, 25021208. The scanning logic is shared through a common virus‑definition update stream for all listed products.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity. Because the vulnerability requires a local user to supply a specially crafted zip file, the attack surface is confined to a local context. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Updating to virus‑definition build 25021208 or later removes the flaw across all Gen Digital products that consume the shared stream. Until such updates are applied, the risk remains moderate to high for users handling untrusted archives.
OpenCVE Enrichment