
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-3500 is an Integer Overflow or Wraparound vulnerability (CWE-190) in Avast Antivirus on Windows that allows privilege escalation. It affects Avast Antivirus versions from 25.1.981.6 up to (but not including) 25.3. The vulnerability was published on December 1, 2025, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, ZDI). The assigning CNA is NLOK (NortonLifeLock/Gen Digital), and the vulnerability is also tracked as EUVD-2025-200018 (ENISA EUVD).
The root cause is an integer overflow or wraparound condition (CWE-190) within the Avast Antivirus engine on Windows, mapped to CAPEC-92 (Forced Integer Overflow). The vulnerability can be triggered remotely over the network with no privileges required and no user interaction, making it particularly dangerous. When exploited, the integer overflow corrupts memory or control flow in a way that enables an attacker to escalate privileges on the affected system. A public proof-of-concept is available on GitHub (PoC GitHub, ZDI).
Successful exploitation results in complete system compromise on affected Windows hosts running Avast Antivirus 25.1.981.6 through 25.2.x. An attacker can achieve high confidentiality impact (data exfiltration), high integrity impact (unauthorized system modification), and high availability impact (service disruption or full system takeover). The network-based attack vector with no user interaction required significantly broadens the potential attack surface, and compromised endpoints could serve as a pivot point for lateral movement within an organization (Feedly, CyberSecurityNews).
AvastSvc.exe, aswEngSrv.exe) spawning unexpected child processes such as cmd.exe, powershell.exe, or other shells with elevated privileges.Avast has released a fix in Avast Antivirus version 25.3 and later; all users running versions 25.1.981.6 through 25.2.x should upgrade immediately (Gen Digital Advisory). Where possible, enable automatic updates to ensure rapid deployment of the patch across the organization. Until patching is complete, monitor for suspicious privilege escalation activity on systems running vulnerable Avast versions and consider restricting network access to those endpoints. No specific configuration-based workaround has been publicly documented.
The vulnerability received coverage from cybersecurity news outlets including CyberSecurityNews and The Hacker News (in their weekly recap), highlighting the critical CVSS score and public PoC availability (CyberSecurityNews, The Hacker News). The Zero Day Initiative published an advisory (ZDI-25-256), lending additional credibility to the severity assessment (ZDI). Community discussion on Infosec.Exchange noted the availability of the PoC and the network-exploitable nature of the flaw. A separate community discussion on VulnDetect raised concerns about the lack of detailed remediation information from Avast (VulnDetect).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."