Back

HIGH

Avira antivirus engine heap buffer OOB read when scanning a malformed Windows MSI file

Published Jun 12, 2026

Description

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows MSI file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.

This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.56.

Affected products

Remediation

Vendor solution

Upgrade to Avira scan engine build 8.3.70.56 or any later engine release. Builds at or above 8.3.70.56 include the fix.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GEN
Published Jun 12, 2026
Updated Jun 15, 2026
Reserved Jul 2, 2025

CISA Vulnrichment

Updated Jun 15, 2026

NVD

Status Deferred
Modified Oct 7, 2026

Red Hat

No data

ENISA EUVD

Assigner GEN
Published Jun 12, 2026
Updated Jun 15, 2026

GitHub

No data