CVE-2025-7018 PUBLISHED

Avira antivirus engine null pointer dereference when scanning a malformed PE file

Assigner: GEN
Reserved: 02.07.2025 Published: 12.06.2026 Updated: 12.06.2026

Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process.

This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.64.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 5.5

Product Status

Vendor Gen Digital
Product Avira Antivirus
Versions Default: affected
  • affected from 0 to 8.3.70.64 (excl.)

Solutions

Upgrade to Avira scan engine build 8.3.70.64 or any later engine release. Builds at or above 8.3.70.64 include the fix.

Credits

  • Mike Zhang, an independent security researcher reporter

References

Problem Types

  • CWE-476 NULL Pointer Dereference CWE

Impacts

  • CAPEC-125 Denial of Service