CVE-2025-7006: Avast, AVG, Norton Antivirus Denial-of-Service via Use-After-Free in PE Scanning
Avast, AVG, and Norton antivirus products (along with Avast One and Avast Business variants) contain a use-after-free defect in their scanning engine that can crash the antivirus process when it encounters a specially crafted Windows PE file. This is a denial-of-service vulnerability affecting Windows, macOS, and Linux systems running virus definitions older than build 25022500. The vulnerability does not allow attackers to execute code or steal data, but disabling antivirus protection on a system could expose it to other threats.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-590
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-12 / 2026-06-17
NVD description (verbatim)
Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25022500. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2025-7006 is a use-after-free memory safety issue (CWE-590) in the shared Gen Digital virus scanning engine. When the scanner processes a malformed Portable Executable (PE) file, it references stack memory after that memory has been freed, triggering a crash of the antivirus process. The vulnerability resides in the scanning logic distributed via Gen Digital's unified virus definition update stream, which is consumed by multiple consumer and business antivirus products. The issue is platform-agnostic and affects Windows, macOS, and Linux builds. Remediation is delivered through the standard virus definition update mechanism; any installation running VPS definition version 25022500 or later is protected.
Business impact
A successful exploit causes temporary unavailability of antivirus protection on affected endpoints. In environments relying on always-on threat detection, this creates a window of vulnerability during which malware can execute without antivirus intervention. Organizations with centralized endpoint detection and response (EDR) or secondary security controls may mitigate the risk; however, smaller deployments or those using antivirus as a primary defense are more exposed. Recovery typically requires manual process restart or system reboot, introducing operational disruption and requiring incident response overhead.
Affected systems
This vulnerability affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus across Windows, macOS, and Linux platforms. All installations are vulnerable if they use virus definition builds prior to VPS 25022500. Because the scanning engine is shared across Gen Digital's product portfolio, other embedded Gen Digital scanning engines may also be affected; verify your specific product deployments against Gen Digital's advisory.
Exploitability
Exploitation requires user interaction—specifically, the user or an automated process must initiate a scan on a system containing a malformed PE file. This could occur through drive-by download, USB insertion, network share access, or email attachment scanning. The attack surface is broad because PE files are ubiquitous in Windows environments and antivirus products are designed to scan files automatically. No special privileges are required; a local user can trigger a scan on files in shared directories. However, the attack is limited to denial-of-service and does not provide code execution or privilege escalation, reducing the urgency for attackers seeking persistent access.
Remediation
The primary remediation is updating virus definition builds to VPS 25022500 or later. This update flows through the standard virus definition update channel and does not require product version upgrades. Organizations should verify that automatic definition updates are enabled and confirm that deployed systems have refreshed their definitions within the last 24 hours. Check the antivirus product console or logs for the current VPS build number. No configuration changes or product reinstalls are necessary.
Patch guidance
Update virus definition builds to VPS 25022500 or later via your antivirus product's built-in update mechanism or your organization's update management platform. For Avast, AVG, and Norton consumer products, enable automatic updates in settings to ensure continuous protection. For Avast Business Antivirus and other enterprise deployments, use your management console to push the updated definitions to all endpoints. Verify deployment by checking reported VPS build numbers in endpoint reports or console dashboards. Test in a non-critical environment if your organization requires change control; however, antivirus definition updates are typically low-risk and can be deployed immediately to production.
Detection guidance
Monitor antivirus process crashes or service restarts on endpoints running affected versions. Look for event log entries indicating antivirus service termination or restart, particularly if correlated with file scanning activities. Query your centralized antivirus management console for endpoints still running VPS definitions older than 25022500. If you maintain EDR or SIEM infrastructure, alert on unexpected termination of antivirus service processes or repeated restart cycles. Scan your organization's files and network shares for malformed PE files using forensic tools, though crafted proof-of-concept samples may be limited in availability.
Why prioritize this
Although the CVSS score is moderate (5.5), the attack surface is broad—any user can trigger the vulnerability via file scanning—and antivirus is a critical control in most environments. Even temporary loss of protection introduces significant residual risk, especially in organizations without compensating EDR or threat hunting capabilities. Prioritize patching based on your organization's reliance on antivirus as a primary defense and the presence of secondary security controls. Remote work environments with limited IT oversight should be patched urgently.
Risk score, explained
The CVSS v3.1 score of 5.5 (MEDIUM) reflects a local attack vector, low complexity, no privilege requirement, and user interaction required. The impact is limited to availability (denial-of-service) with no confidentiality or integrity compromise. However, the score does not account for the downstream business risk of undefended endpoints or the broad attack surface in multi-user and network-attached file scenarios. Organizations should supplement the CVSS rating with their own risk assessment, considering their security posture, asset criticality, and regulatory obligations.
Frequently asked questions
Can this vulnerability be exploited remotely?
No. The attack vector is local (AV:L), meaning the attacker or user must have access to the system or network share containing the malformed PE file. However, a malicious file can reach the system via email, web download, USB, or network share, and the act of scanning it—often automatic—triggers the crash.
Does this vulnerability allow code execution or data theft?
No. This is strictly a denial-of-service vulnerability. It crashes the antivirus process but does not allow the attacker to execute commands, escalate privileges, or exfiltrate data. Its impact is limited to temporary loss of antivirus protection.
Do I need to upgrade my antivirus product, or just update the definitions?
Definitions only. The fix is delivered via the virus definition update stream (VPS 25022500 or later). You do not need to upgrade the antivirus product version itself. Enable automatic definition updates in your antivirus settings or push the update via your management console.
How quickly should I patch this?
Prioritize this within your normal change window, typically within 1-2 weeks for non-critical systems and within days for high-risk or critical assets. Because it is a definition update with low deployment risk and moderate business impact, many organizations deploy immediately or within 24-48 hours.
This analysis is based on publicly available information and Gen Digital's advisory as of the publication date. CVSS scores and vulnerability details are subject to change as new information emerges. Organizations should verify compatibility and testing requirements with their antivirus vendor before deploying updates in production. This document does not constitute legal, compliance, or insurance advice. Consult your internal security and legal teams for decisions affecting regulated environments or business-critical systems. SEC.co makes no warranty regarding the accuracy, completeness, or applicability of this guidance to your organization. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-47328MEDIUMUbuntu Linux Kernel Memory Corruption via AppArmor SAUCE Patches
- CVE-2016-20064MEDIUMWP Vault 0.8.6.6 Arbitrary File Read via Directory Traversal
- CVE-2016-20067MEDIUMWordPress CP Polls CSRF Vulnerability
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2016-20074MEDIUMWordPress Lazy Content Slider CSRF Vulnerability – Patch & Detection Guide
- CVE-2016-20077MEDIUMWordPress Photocart Link Plugin Local File Inclusion Vulnerability
- CVE-2016-20078MEDIUMWordPress IMDb Profile Widget Local File Inclusion Vulnerability
- CVE-2016-20079MEDIUMWordPress Dharma Booking Local File Inclusion Vulnerability