MEDIUM 5.5

CVE-2025-7010: Avast Antivirus Stack Overflow DoS Vulnerability – VPS Definition Patch Required

A stack overflow flaw in the antivirus engines used by Avast, AVG, Norton, and related products can crash the scanning process when it encounters a specially crafted PDF file. The vulnerability stems from unchecked recursive calls in the PDF parsing logic, which is shared across multiple Gen Digital consumer and business antivirus products via a centralized virus definition update channel. An attacker who can deliver a malformed PDF to a user could trigger a denial-of-service condition, temporarily disabling real-time malware protection until the antivirus process restarts.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-674
Affected products
0 configuration(s)
Published / Modified
2026-06-12 / 2026-06-17

NVD description (verbatim)

Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malformed PDF file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021208. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2025-7010 is a stack overflow vulnerability (CWE-674: Uncontrolled Recursion) affecting the Gen Digital virus definition engine used across Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux platforms. The vulnerability exists in PDF file scanning logic that does not properly validate recursion depth, allowing a malformed PDF to exhaust the stack and crash the scanning engine. Because the vulnerable code is delivered through a shared virus definition update stream (VPS) rather than product-specific binaries, remediation is centralized: all products consuming VPS build 25021208 or later are mitigated, regardless of their individual product versions.

Business impact

Organizations relying on Avast, AVG, or Norton antivirus may experience temporary lapses in malware protection if users open malformed PDFs, particularly if those PDFs are delivered via email or downloads. The denial-of-service is localized to the scanning process and does not compromise system integrity or data confidentiality, but it could allow malicious files to bypass real-time scanning until the antivirus restarts. For enterprises with strict compliance requirements around continuous endpoint protection, repeated crashes could trigger audit findings. The risk is amplified in environments where users frequently receive unsolicited PDFs or where antivirus processes lack automatic recovery mechanisms.

Affected systems

The vulnerability affects the following products on Windows, macOS, and Linux: Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus. Critically, the vulnerable code is embedded in the shared Gen Digital virus definition engine; mitigation depends on VPS build version, not individual product releases. Any installation of these products with virus definitions older than VPS 25021208 is vulnerable. Other Gen Digital products that embed the same scanning engine may also be affected; administrators should verify their specific product line's status with the vendor.

Exploitability

Exploitation requires local user interaction: an attacker must persuade or trick a user into scanning a malformed PDF file, typically via email attachment, download link, or removable media. The attack surface is broad because PDF is ubiquitous, but it is not remotely exploitable without user action. The CVSS score of 5.5 (Medium) reflects the local attack vector, low complexity, and no privileges required, balanced against limited scope and availability-only impact. This is not an in-the-wild weaponized exploit scenario; it is a denial-of-service condition triggered by malformed file content. Detection in the wild would likely require users to report antivirus crashes following specific file interactions.

Remediation

The authoritative remediation is updating the virus definition engine to VPS build 25021208 or later. Because this update flows through Gen Digital's centralized update channel, most users with automatic definition updates enabled will receive the patch automatically within hours or days of release. Manual remediation involves checking the current VPS build version in the affected product's settings and manually triggering a virus definition update if automatic updates are disabled. Administrators managing multiple endpoints should verify VPS build numbers across their fleet and ensure update policies are enforced. No product reinstallation or rollback is necessary.

Patch guidance

Verify that your Avast, AVG, Norton, Avast One, or Avast Business Antivirus installation has received virus definition updates at or above VPS build 25021208. In most products, this can be confirmed in Settings > Update or similar menu. Enable automatic virus definition updates if they are not already active, as the patch is delivered through the routine VPS channel. If your organization uses a centralized update server or proxy, confirm that it is configured to download and distribute the latest VPS builds. Test the update deployment on a representative sample of endpoints before assuming fleet-wide compliance. No reboot is required after a VPS update in most cases, but verify product-specific guidance from the vendor.

Detection guidance

Monitor for repeated antivirus process crashes (e.g., avast.exe, avgui.exe, or Norton process terminations) coinciding with PDF file scans. Check antivirus logs for stack overflow or recursion-depth-related error messages. Correlation between user reports of 'antivirus stopped working' and PDF file interactions is a leading indicator. Endpoint Detection and Response (EDR) tools should alert on abnormal antivirus process terminations. Verify VPS build versions across your endpoint fleet via inventory or management console queries to identify systems still running pre-25021208 definitions. Hunt for any malformed PDFs that may have been introduced to your environment via email gateways or file repositories; however, note that this is a high-effort hunt with low probability of detection without prior incident indicators.

Why prioritize this

This vulnerability merits medium-priority patching within normal maintenance windows. It requires user interaction and local access, and the impact is denial-of-service rather than data breach or privilege escalation. However, it affects widely deployed consumer and business antivirus products, meaning many organizations are likely vulnerable. The centralized nature of the fix—delivered via VPS channel—means remediation is straightforward for organizations with functioning update processes. Prioritize over low-severity vulnerabilities but defer behind critical RCE or authentication bypass issues. If your organization has evidence of malformed PDFs in circulation or antivirus crashes correlated with PDF handling, elevate to higher priority.

Risk score, explained

The CVSS 3.1 score of 5.5 (Medium) reflects: Attack Vector Local (antivirus runs on the endpoint and must process user-supplied files), Attack Complexity Low (any malformed PDF can trigger the overflow), Privileges Required None (user context is sufficient), User Interaction Required (user or admin must trigger scanning), Scope Unchanged (only the antivirus process is affected), Confidentiality None, Integrity None, Availability High (antivirus process is denied service). The score appropriately captures a nuisance-level DoS that does not expose data or escalate privileges but does temporarily cripple a critical security control.

Frequently asked questions

Can this vulnerability be exploited remotely?

No. Exploitation requires that a user or system process scans a malformed PDF file. An attacker can distribute the PDF via email or web download, but the user must trigger the scan (e.g., open the file or have the antivirus auto-scan it). Remote code execution over the network is not possible.

Which virus definition build version am I currently running, and how do I update it?

In most Avast, AVG, or Norton products, navigate to Settings, Help, or Update sections and look for 'Virus Definitions' or 'VPS' version. The current version should be displayed. If it is older than 25021208, manually trigger an update by clicking 'Update Now' or similar. If automatic updates are enabled, your system should already have the latest definitions. Consult your specific product's user manual for exact steps.

Does this vulnerability affect my Mac or Linux systems?

Yes. The vulnerability affects Avast, AVG, Norton, and related products on Windows, macOS, and Linux. The shared virus definition engine is platform-agnostic. Ensure all your endpoints—regardless of OS—are running VPS 25021208 or later.

What happens if a user encounters a malformed PDF while this vulnerability is unpatched?

The antivirus scanning process will likely crash, terminating real-time protection until the process is manually restarted or automatically recovers. The user may see an error message or notification that antivirus has stopped. The malformed PDF itself may not be quarantined, and subsequent files may not be scanned until the antivirus restarts. Malware in the PDF would not be detected during that window.

This analysis is provided for informational purposes and does not constitute legal or professional advice. Organizations are responsible for assessing the applicability of this vulnerability to their environment and implementing patches according to their own risk management policies. Patch versions and build numbers referenced here are derived from the published vendor advisory and should be verified against the official Gen Digital security advisory before deployment. SEC.co does not warrant the accuracy or completeness of this analysis and does not assume liability for decisions made based on this content. Always consult official vendor documentation and your security team before implementing mitigations. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).