CVE-2025-9032: Heap Buffer Out-of-Bounds Read Vulnerability in Avira Antivirus Engine
Summary
A heap buffer out-of-bounds read vulnerability (CVE-2025-9032) has been discovered in the Avira Antivirus engine. The flaw occurs when scanning a malformed Windows PE file, potentially allowing local execution of code or denial-of-service of the antivirus engine process. The vulnerability affects Avira Antivirus on Windows, macOS, and Linux for engine builds prior to version 8.3.70.98.
Source

Key quotes
· 2 pulledHeap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.
This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98.
You might also wanna read
Technical Analysis of CVE-2025-53149: Heap-based Buffer Overflow in Windows Kernel Streaming Driver
Researchers discovered CVE-2025-53149, a heap-based buffer overflow vulnerability in the Windows Kernel Streaming WOW Thunk Service Driver (
Heap-Buffer-Overflow Vulnerability Discovered in FFmpeg's EXIF Writer for Image Formats
The article details the discovery of a four-byte heap-buffer-overflow vulnerability in FFmpeg's EXIF writer when processing extra IFD (Image
Proof-of-Concept Exploit Released for Critical NGINX Heap Buffer Overflow (CVE-2026-42945)
A proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow vulnerability in NGINX's ngx_http_rewrite_module that has exi
First CVE Vulnerability Discovered in Linux Kernel's Rust Code
The first CVE vulnerability has been assigned to Rust code in the Linux kernel, specifically affecting the Android Binder rewrite in Rust. T
Exploiting CVE-2024-50264: Using Kernel-Hack-Drill to Overcome Linux Kernel Vulnerability Challenges
This technical article details the exploitation of CVE-2024-50264, a challenging Linux kernel vulnerability that won the Pwnie Award 2025 fo
Critical Buffer Overflow Vulnerability Discovered in cURL Cookie Parsing Mechanism
A security researcher discovered a critical stack-based buffer overflow vulnerability in cURL's cookie parsing mechanism that can lead to re
Comments
Sign in to join the conversation.
No comments yet. Be the first.
