Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.64.
History

Mon, 15 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 13 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Gen Digital
Gen Digital avira Antivirus
Vendors & Products Gen Digital
Gen Digital avira Antivirus

Fri, 12 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Description Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.64.
Title Avira antivirus engine null pointer dereference when scanning a malformed PE file
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GEN

Published: 2026-06-12T22:13:49.820Z

Updated: 2026-06-15T16:01:44.198Z

Reserved: 2025-07-02T12:01:13.717Z

Link: CVE-2025-7018

cve-icon Vulnrichment

Updated: 2026-06-15T16:01:37.583Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T22:16:49.467

Modified: 2026-06-15T20:49:19.213

Link: CVE-2025-7018

cve-icon Redhat

No data.