Description
Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process.

This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25020100.



The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Published: 2026-06-12
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack overflow in Avast Antivirus occurs when a malformed Office Open XML file is scanned, potentially leading to a denial of service of the antivirus process. The flaw is a stack buffer overrun identified as CWE-121, which can crash the application but does not allow code execution or data disclosure.

Affected Systems

The vulnerability affects Gen Digital products including Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One and Avast Business Antivirus running on Windows, macOS, and Linux. Versions built with virus definition updates prior to VPS 25020100 are vulnerable; all builds at or above that definition stream are not affected.

Risk and Exploitability

The CVSS score of 5.5 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Attackers may trigger the issue by providing the user with a crafted Office file that is scanned by the antivirus, implying a local or social‑engineering attack vector. While a denial of service can interrupt protection, there is no evidence of remote code execution or broader compromise.

Generated by OpenCVE AI on June 12, 2026 at 23:20 UTC.

Remediation

Vendor Solution

Install virus definitions VPS 25020100 or any later virus-definition update. All builds at or above VPS 25020100 include the fix; staying current on definitions is required.


OpenCVE Recommended Actions

  • Update virus definitions to VPS 25020100 or any later update for all Gen Digital antivirus products.
  • Ensure all installations remain on the current definition stream so that future builds also incorporate the fix.
  • Monitor official Gen Digital security advisories for any additional patches or guidance.

Generated by OpenCVE AI on June 12, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Description Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25020100. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Title Avast antivirus stack overflow when scanning a malformed Office Open XML file
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GEN

Published:

Updated: 2026-06-12T22:14:19.144Z

Reserved: 2025-07-02T12:03:39.699Z

Link: CVE-2025-7019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-12T22:16:49.590

Modified: 2026-06-12T22:16:49.590

Link: CVE-2025-7019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T23:30:08Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow