CVE-2025-7007: Null pointer dereference in Avast Antivirus on macOS (16.0.0) or Linux (3.0.3)
NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7007?
CVE-2025-7007 has been classified as a high severity vulnerability due to its potential to crash the antivirus process.
How do I fix CVE-2025-7007?
To fix CVE-2025-7007, update to the latest version of Avast Antivirus provided by the vendor.
Which versions are affected by CVE-2025-7007?
CVE-2025-7007 affects Avast Antivirus version 16.0.0 and Avast Antivirus on Linux version 3.0.3.
What causes CVE-2025-7007?
CVE-2025-7007 is caused by a NULL Pointer Dereference vulnerability when scanning a malformed Windows PE file.
Is there a workaround for CVE-2025-7007?
A possible workaround for CVE-2025-7007 is to avoid scanning untrusted or potentially malformed Windows PE files until a patch is applied.