← Vulnerability feed

Vulnerability record · CVE-2008-6962 · published 13 August 2009

CVE-2008-6962: Avira antivir improper input validation vulnerability

Avira · Antivir

Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer.

7.2 CVSS 2.0 High EPSS 0.65% · top 50.7% CWE-20 · Improper input validation
7.2CVSS 2.0 base score
0.65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-6962 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2974Avira antivir vulnerabilityBuffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a craft…EPSS 7.5%7.8CVE-2007-2972Avira antivir vulnerabilityThe file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a c…EPSS 3.4%7.8CVE-2007-2973Avira antivir vulnerabilityAvira Antivir Antivirus before 7.03.00.09 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed TA…EPSS 3.4%7.8CVE-2007-1673Amavis vulnerabilityunzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a …EPSS 3.2%7.8CVE-2007-1671Avira antivir personal vulnerabilityavpack32.dll before 7.3.0.6 in Avira AntiVir allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry s…EPSS 2.0%7.2CVE-2009-2761Avira antivir vulnerabilityUnquoted Windows search path vulnerability in the scheduler (sched.exe) in Avira AntiVir, AntiVir Premium, Premium Security Suite, and AntiVir Profes…EPSS 0.35%7.2CVE-2006-1274Avira antivir personal vulnerabilityClassic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain pri…EPSS 0.38%5.5CVE-2013-4602Avira antivir mailgate uncontrolled resource consumption vulnerabilityA Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engi…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2008-6962), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.