CVE-2025-14098 PUBLISHED

Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file

Assigner: GEN
Reserved: 05.12.2025 Published: 12.06.2026 Updated: 12.06.2026

Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.

This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Gen Digital
Product Avira Antivirus
Versions Default: affected
  • affected from 0 to 8.3.70.104 (excl.)

Solutions

Upgrade to Avira scan engine build 8.3.70.104 or any later engine release. Builds at or above 8.3.70.104 include the fix.

Credits

  • Mike Zhang, an independent security researcher reporter

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE
  • CWE-190 Integer Overflow or Wraparound CWE

Impacts

  • CAPEC-549 Local Execution of Code