CVE-2025-7011
Last modified
CVE-2025-7011 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds from 25020100 before 25021208. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds from 25020100 before 25021208. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-7011?
How severe is CVE-2025-7011?
How do I fix CVE-2025-7011?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-70099A NULL pointer dereference in the ext4_dir_en_get_name_len f…7.5
- CVE-2025-7010Stack overflow vulnerability due to uncontrolled recursion i…5.5
- CVE-2025-70100A divide-by-zero vulnerability in the ext4_block_set_lb_size…5.5
- CVE-2025-70101An out-of-bounds read in the ext4_ext_binsearch_idx function…6.5
- CVE-2025-70102A NULL pointer dereference occurs in Roy Marples NetworkConf…6.3
- CVE-2025-70103Heap buffer overflow vulnerability in libjxl 0.12.0 via craf…7.3
- CVE-2025-70116A NULL pointer dereference in GPAC MP4Box: when parsing cert…4.3
- CVE-2025-7012An issue in Cato Networks' CatoClient for Linux, before vers…8.6
- CVE-2025-70121An array index out of bounds vulnerability in the AMF compon…7.5
- CVE-2025-70122A heap buffer overflow vulnerability in the UPF component of…7.5
- CVE-2025-70123An improper input validation and protocol compliance vulnera…7.5
- CVE-2025-70128A Stored Cross-Site Scripting (XSS) vulnerability exists in …6.1
Are you affected by CVE-2025-7011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
