This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98.
Project Subscriptions
No advisories yet.
Solution
Upgrade to Avira scan engine build 8.3.70.98 or any later engine release. Builds at or above 8.3.70.98 include the fix.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the anitvirus engine process.This issue affects Antivirus: from 8.3.70.94 before 8.3.70.98. | Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98. |
| Title | Scanning a malformed file in Avast Antivirus 8.3.70.94 on MacOS may result in remote code execution | Avira antivirus engine heap buffer OOB read when scanning a malformed file |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 01 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Avast Avast antivirus |
|
| Vendors & Products |
Apple
Apple macos Avast Avast antivirus |
Mon, 01 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Scanning a malformed file in Avast Antivirus 8.3.70.94 on MacOS may result in remote code execution | |
| Metrics |
ssvc
|
Mon, 01 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the anitvirus engine process.This issue affects Antivirus: from 8.3.70.94 before 8.3.70.98. | |
| Weaknesses | CWE-122 CWE-125 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NLOK
Published:
Updated: 2026-06-12T22:32:51.689Z
Reserved: 2025-07-30T11:48:44.820Z
Link: CVE-2025-8351
Updated: 2025-12-01T15:58:22.538Z
Status : Deferred
Published: 2025-12-01T16:15:57.857
Modified: 2026-06-12T23:16:28.253
Link: CVE-2025-8351
No data.
OpenCVE Enrichment
Updated: 2025-12-01T21:27:19Z