CVE Feed

    Dashboard / CVE / CVE-2025-7011

    CVE-2025-7011

    Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds from 25020100 before 25021208. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.

    Published:Jun 12, 2026
    Last Modified:Jun 15, 2026
    EPS:Jun 12, 2026
    EPSS Score:0.00146
    CVSS Score:7.8

    Affected Products

    Vendor
    Gen Digital
    Product
    Avast Antivirus
    Vendor
    Gen Digital
    Product
    Avast Business Antivirus
    Vendor
    Gen Digital
    Product
    Avast One
    Vendor
    Gen Digital
    Product
    Avg Antivirus
    Vendor
    Gen Digital
    Product
    Norton Antivirus

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High