Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-7006 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25022500. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-590Free of Memory not on the Heap[email protected]

Affected Products

ProductVersions
Avast Antivirus
< VPS 25022500

CPE

  • cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
AVG Antivirus
< VPS 25022500

CPE

  • cpe:2.3:a:avg:anti-virus:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:avg_antivirus:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
Norton Antivirus
< VPS 25022500

CPE

  • cpe:2.3:a:symantec:norton_antivirus:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
Avast One
< VPS 25022500

CPE

  • cpe:2.3:a:avast:avast:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:premier:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:avast_internet_security:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:free_antivirus:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:antivirus_pro:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
Avast Business Antivirus
< VPS 25022500

CPE

  • cpe:2.3:a:avast:business_security:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-7006
NVD Published Date:
Jun 12, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-7006 Details - Not Deferred