CVE-2025-3500
CRITICALAvast Antivirus 25.1.981.6-25.3 - Privilege Escalation via Integer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-3500. PoCs published by adminlove520, chicken3962.
AI-analyzed exploit summary The repository claims to provide a PoC for CVE-2025-3500 but lacks actual exploit code, instead directing users to external downloads. The README contains detailed technical descriptions but no functional code, raising suspicions of a social engineering lure.
Description
Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
Exploits (2)
The repository claims to provide a PoC for CVE-2025-3500 but lacks actual exploit code, instead directing users to external downloads. The README contains detailed technical descriptions but no functional code, raising suspicions of a social engineering lure.
This repository provides a proof-of-concept exploit for CVE-2025-3500, an integer overflow vulnerability in Avast Antivirus 25.1.981.6, leading to privilege escalation via crafted API calls. The exploit includes a compiled binary and batch script to trigger the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H