Impact
A stack overflow in Avast Antivirus occurs when a malformed Office Open XML file is scanned, potentially leading to a denial of service of the antivirus process. The flaw is a stack buffer overrun identified as CWE-121, which can crash the application but does not allow code execution or data disclosure.
Affected Systems
The vulnerability affects Gen Digital products including Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One and Avast Business Antivirus running on Windows, macOS, and Linux. Versions built with virus definition updates prior to VPS 25020100 are vulnerable; all builds at or above that definition stream are not affected.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Attackers may trigger the issue by providing the user with a crafted Office file that is scanned by the antivirus, implying a local or social‑engineering attack vector. While a denial of service can interrupt protection, there is no evidence of remote code execution or broader compromise.
OpenCVE Enrichment