A critical flaw identified in Avast Free Antivirus, tracked as CVE-2025-3500, may enable attackers to achieve elevated system access by targeting a weakness in the software’s kernel-level driver. The issue, which received a severity score of 8.8, is linked to the aswbidsdriver component, where improper handling of user input may lead to an integer overflow. If this flaw is exploited, it could let an attacker run code with elevated privileges, potentially compromising the entire system. The vulnerability was detailed in an advisory by the Zero Day Initiative (ZDI) on April 24, 2025. According to the report, an attacker would first need access to the system with limited user rights. From there, they could exploit the flaw to execute malicious code at the kernel level, giving them deep control over the device. While the attack must originate locally, the potential damage is significant once access is gained. The vulnerability was first brought to Avast’s attention by cybersecurity expert Baris Akkaya, who disclosed it responsibly on April 2, 2025. Avast addressed the issue by delivering a fix through its software update, released as version 25.3.9983.922. Anyone using versions between 2016.11.1.2262 and 20.1.2397 should upgrade to the latest release without delay to eliminate exposure to this vulnerability. Given Avast’s large user base, particularly among home users, the risk posed by this vulnerability is notable. Security professionals recommend enabling automatic updates and avoiding routine use of administrator accounts to limit the potential impact of future exploits.
Cybersecurity researchers have reported a major spike in suspicious scans targeting Palo Alto Networks login portals, signaling potential reconnaissance activity by malicious actor...
Recently, a critical flaw, designated CVE-2025-59489, was discovered in Unity Technologies real-time game engine and game development platform. Unity Editor versions after 2017.1, ...
Virtual Private Networks (VPNs) are widely used to protect online privacy, secure communication, and enable remote access, especially on mobile devices. However, a disturbing trend...