Impact
The vulnerability is a null pointer dereference in the Avira Antivirus engine triggered while parsing a malformed Windows Portable Executable file. The flaw does not provide direct code execution or information disclosure; instead, it causes the antivirus process to crash, resulting in a denial of service for the scanner. The weakness is classified as CWE‑476.
Affected Systems
Avira Antivirus, released by Gen Digital, is affected on Windows, macOS, and Linux platforms. Any engine build prior to 8.3.70.64 may crash when it receives a malformed PE file.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need to deliver a crafted PE file to the engine, which could be achieved via file upload, email attachment, or local execution when the antivirus scans a target directory. The risk is limited to causing a service interruption rather than privilege escalation or data theft.
OpenCVE Enrichment