Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-7008 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file with .NET metadata may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021310. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-125Out-of-bounds Read[email protected]

Affected Products

ProductVersions
Avast Antivirus
< VPS 25021310

CPE

  • cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
AVG Antivirus
< VPS 25021310

CPE

  • cpe:2.3:a:avg:anti-virus:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:avg_antivirus:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
Norton Antivirus
< VPS 25021310

CPE

  • cpe:2.3:a:symantec:norton_antivirus:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
Avast One
< VPS 25021310

CPE

  • cpe:2.3:a:avast:avast:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:premier:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:avast_internet_security:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:free_antivirus:*:*:*:*:*:*:*:*
  • cpe:2.3:a:avast:antivirus_pro:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
Avast Business Antivirus
< VPS 25021310

CPE

  • cpe:2.3:a:avast:business_security:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-7008
NVD Published Date:
Jun 12, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-7008 Details - Not Deferred