Avast's vulnerability footprint centers on a modestly sized but widely deployed consumer and professional antivirus product portfolio. The vendor's disclosures span a meaningful range of serious outcomes, and vulnerabilities affecting its products have a moderate tendency toward public exploit availability. The exposure recurs across its antivirus product line through weakness classes including improper link resolution before file access, memory-safety violations such as buffer overflows and out-of-bounds writes, and improper input validation—issues endemic to security software that must parse and process untrusted samples. Defenders should treat Avast advisories as relevant to endpoint security posture broadly, since the antivirus layer's security directly affects the hosts it protects; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Avast over time
Signals from CVEs in this vendor scope (79 CVEs).
79 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3126HIGH Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DL | Aug 26, 2010 | 9.3 | 40 | NO | YES |
CVE-2016-3986HIGH Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing. | Apr 12, 2016 | 7.8 | 39 | NO | YES |
CVE-2025-3500CRITICAL Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. | Dec 1, 2025 | 9.8 | 32 | NO | NO |
CVE-2022-4291CRITICAL The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the a | Dec 8, 2022 | 10.0 | 31 | NO | NO |
CVE-2017-8307CRITICAL In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary | Apr 27, 2017 | 9.8 | 31 | NO | NO |
CVE-2020-10867CRITICAL An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access | Apr 1, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-23907CRITICAL An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact i | Apr 21, 2021 | 9.8 | 29 | NO | NO |
CVE-2010-0705HIGH Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users | Feb 25, 2010 | 7.2 | 29 | NO | YES |
CVE-2009-4049HIGH Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or | Nov 23, 2009 | 7.2 | 29 | NO | YES |
CVE-2009-3522HIGH Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial o | Oct 1, 2009 | 7.2 | 29 | NO | YES |
Signals from CVEs in this vendor scope (79 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avast.
Media articles that mention a CVE ID that affects a product developed by Avast — matched by CVE ID, not by vendor name.