CVE-2025-10905
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-11

Last updated on: 2025-11-11

Assigner: NortonLifeLock Inc.

Description
Collision in MiniFilter driver in Avast Software Avast Free Antivirus  before 25.9  on Windows allows a local attacker with administrative privileges to disable real-time protection and self-defense mechanisms.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-11
Last Modified
2025-11-11
Generated
2026-06-16
AI Q&A
2025-11-11
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
avast avast_free_antivirus *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a collision in the MiniFilter driver of Avast Free Antivirus before version 25.9 on Windows. It allows a local attacker who already has administrative privileges to disable the software's real-time protection and self-defense mechanisms.

Impact Analysis

If exploited, this vulnerability can allow an attacker with administrative access to disable Avast Free Antivirus's real-time protection and self-defense features, potentially leaving the system unprotected against malware and other threats.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-10905. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart