VYPR
Medium severity5.5NVD Advisory· Published Jun 12, 2026

CVE-2025-7006

CVE-2025-7006

Description

Avast/AVG/Norton antivirus products have a use-after-free in PE file scanning, leading to denial-of-service; fixed in VPS 25022500.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Avast/AVG/Norton antivirus products have a use-after-free in PE file scanning, leading to denial-of-service; fixed in VPS 25022500.

Vulnerability

A use-after-free on the stack exists in the virus definition scanning engine shared by Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux. The flaw is triggered when the scan routine processes a malformed Windows PE file. Affected versions are those with virus definition builds before VPS 25022500 [1].

Exploitation

An attacker can send a specifically crafted PE file to a target system. No special authentication or network position is required beyond the ability to deliver the file to a location the antivirus will scan (e.g., via email, web download, or local write access). When the antivirus engine parses the malformed PE file, the stack memory corruption occurs, causing the process to crash [1].

Impact

Successful exploitation causes the antivirus process to terminate, resulting in a denial-of-service condition. The security software stops providing real-time protection until manually restarted. There is no indication of information disclosure or code execution [1].

Mitigation

Gen Digital released virus definition update VPS 25002500 on or before 2026-06-12, which remediates the issue. All installations with a build at or above that version are unaffected. Users should ensure automatic updates are enabled or manually apply the latest virus definitions [1].

AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.