CVE-2025-3500 is a critical Integer Overflow or Wraparound vulnerability affecting Avast Antivirus versions 25.1.981.6 and earlier on Windows, allowing for Privilege Escalation. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness. Organizations using affected Avast Antivirus versions should update to version 25.3 or later immediately to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 25.1.981.6, < 25.3CPE matchmatch criteria | cpe:2.3:a:avast:antivirus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.