CVE-2016-4025 Details
Description
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.nettitude.com/blog/escaping-avast-sandbox-using-single-ioctl-cve-2016-4025/ | CVE | Technical DescriptionThird Party Advisory |
| https://labs.nettitude.com/blog/escaping-avast-sandbox-using-single-ioctl-cve-2016-4025/ | [email protected] | Technical DescriptionThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-254 | 7PK - Security Features | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| avast business security | 11.1.2241 11.1.2245 11.1.2253 11.1.2260 11.1.2261 11.1.2262 |
CPE
Remediation
| |
| avast free antivirus | 11.1.2241 11.1.2245 11.1.2253 11.1.2260 11.1.2261 11.1.2262 |
CPE
Remediation
| |
| avast internet security | 11.1.2241 11.1.2245 11.1.2253 11.1.2260 11.1.2261 11.1.2262 |
CPE
Remediation
| |
| avast premier | 11.1.2241 11.1.2245 11.1.2253 11.1.2260 11.1.2261 11.1.2262 |
CPE
Remediation
| |
| avast pro antivirus | 11.1.2241 11.1.2245 11.1.2253 11.1.2260 11.1.2261 11.1.2262 |
CPE
Remediation
| |
| avast email server security | <= 8.0.1609 8.0.1606 |
CPE
Remediation
| |
| avast endpoint protection | <= 8.0.1609 8.0.1606 |
CPE
Remediation
| |
| avast endpoint protection plus | 8.0.1606 8.0.1609 |
CPE
Remediation
| |
| avast endpoint protection suite | <= 8.0.1609 8.0.1606 |
CPE
Remediation
| |
| avast endpoint protection suite plus | <= 8.0.1609 8.0.1606 |
CPE
Remediation
| |
| avast file server security | <= 8.0.1609 8.0.1606 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 4, 2016 | CVE Translated | [email protected] |
| Nov 4, 2016 | Modified Analysis | [email protected] |
| Nov 4, 2016 | Initial Analysis | [email protected] |