CVE-2016-4025
Summary
| CVE | CVE-2016-4025 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-11-03 10:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call. |
Risk And Classification
Primary CVSS: v3.0 5.5 MEDIUM from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.000640000 probability, percentile 0.196870000 (date 2026-05-10)
Problem Types: CWE-254 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 2.1 | AV:L/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Avast | Business Security | 11.1.2241 | All | All | All |
| Application | Avast | Business Security | 11.1.2245 | All | All | All |
| Application | Avast | Business Security | 11.1.2253 | All | All | All |
| Application | Avast | Business Security | 11.1.2260 | All | All | All |
| Application | Avast | Business Security | 11.1.2261 | All | All | All |
| Application | Avast | Business Security | 11.1.2262 | All | All | All |
| Application | Avast | Email Server Security | 8.0.1606 | All | All | All |
| Application | Avast | Email Server Security | All | All | All | All |
| Application | Avast | Endpoint Protection | 8.0.1606 | All | All | All |
| Application | Avast | Endpoint Protection | All | All | All | All |
| Application | Avast | Endpoint Protection Plus | 8.0.1606 | All | All | All |
| Application | Avast | Endpoint Protection Plus | 8.0.1609 | All | All | All |
| Application | Avast | Endpoint Protection Suite | 8.0.1606 | All | All | All |
| Application | Avast | Endpoint Protection Suite | All | All | All | All |
| Application | Avast | Endpoint Protection Suite Plus | 8.0.1606 | All | All | All |
| Application | Avast | Endpoint Protection Suite Plus | All | All | All | All |
| Application | Avast | File Server Security | 8.0.1606 | All | All | All |
| Application | Avast | File Server Security | All | All | All | All |
| Application | Avast | Free Antivirus | 11.1.2241 | All | All | All |
| Application | Avast | Free Antivirus | 11.1.2245 | All | All | All |
| Application | Avast | Free Antivirus | 11.1.2253 | All | All | All |
| Application | Avast | Free Antivirus | 11.1.2260 | All | All | All |
| Application | Avast | Free Antivirus | 11.1.2261 | All | All | All |
| Application | Avast | Free Antivirus | 11.1.2262 | All | All | All |
| Application | Avast | Internet Security | 11.1.2241 | All | All | All |
| Application | Avast | Internet Security | 11.1.2245 | All | All | All |
| Application | Avast | Internet Security | 11.1.2253 | All | All | All |
| Application | Avast | Internet Security | 11.1.2260 | All | All | All |
| Application | Avast | Internet Security | 11.1.2261 | All | All | All |
| Application | Avast | Internet Security | 11.1.2262 | All | All | All |
| Application | Avast | Premier | 11.1.2241 | All | All | All |
| Application | Avast | Premier | 11.1.2245 | All | All | All |
| Application | Avast | Premier | 11.1.2253 | All | All | All |
| Application | Avast | Premier | 11.1.2260 | All | All | All |
| Application | Avast | Premier | 11.1.2261 | All | All | All |
| Application | Avast | Premier | 11.1.2262 | All | All | All |
| Application | Avast | Pro Antivirus | 11.1.2241 | All | All | All |
| Application | Avast | Pro Antivirus | 11.1.2245 | All | All | All |
| Application | Avast | Pro Antivirus | 11.1.2253 | All | All | All |
| Application | Avast | Pro Antivirus | 11.1.2260 | All | All | All |
| Application | Avast | Pro Antivirus | 11.1.2261 | All | All | All |
| Application | Avast | Pro Antivirus | 11.1.2262 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Escaping the Avast sandbox — Nettitude Labs | af854a3a-2127-422b-91ae-364da2661108 | labs.nettitude.com | Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.