CVE-2025-8351: Avira antivirus engine heap buffer OOB read when scanning a malformed file
Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.
This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8351?
CVE-2025-8351 is categorized as a critical severity vulnerability due to its potential for local code execution and denial-of-service.
How do I fix CVE-2025-8351?
To remediate CVE-2025-8351, update Avast Antivirus to version 8.3.70.98 or later.
What types of attacks can CVE-2025-8351 facilitate?
CVE-2025-8351 can facilitate local execution of code and potentially cause a denial-of-service on the antivirus engine.
Which versions of Avast Antivirus are affected by CVE-2025-8351?
CVE-2025-8351 affects Avast Antivirus versions from 8.3.70.94 up to but not including 8.3.70.98.
Can CVE-2025-8351 be exploited remotely?
CVE-2025-8351 requires local access for exploitation, as it pertains to scanning malformed files.