Lack of file validation in Avast Business Antivirus for Linux allows writing untrusted update files
Vulnerability Description
Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4134
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- FIS Securtiy
- Nông Hoàng Tú
More from Avast
View All →Affected Vendor
Avast
View all reports →