CVE-2016-4025: Avast Business Security

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.

Affected products

  • Avast Business Security: version 11.1.2241 only; version 11.1.2245 only; version 11.1.2253 only; version 11.1.2260 only; version 11.1.2261 only; version 11.1.2262 only
  • Avast Email Server Security: up to and including 8.0.1609; version 8.0.1606 only
  • Avast Endpoint Protection: up to and including 8.0.1609; version 8.0.1606 only
  • Avast Endpoint Protection Plus: version 8.0.1606 only; version 8.0.1609 only
  • Avast Endpoint Protection Suite: up to and including 8.0.1609; version 8.0.1606 only
  • Avast Endpoint Protection Suite Plus: up to and including 8.0.1609; version 8.0.1606 only
  • Avast File Server Security: up to and including 8.0.1609; version 8.0.1606 only
  • Avast Free Antivirus: version 11.1.2241 only; version 11.1.2245 only; version 11.1.2253 only; version 11.1.2260 only; version 11.1.2261 only; version 11.1.2262 only
  • Avast Internet Security: version 11.1.2241 only; version 11.1.2245 only; version 11.1.2253 only; version 11.1.2260 only; version 11.1.2261 only; version 11.1.2262 only
  • Avast Premier: version 11.1.2241 only; version 11.1.2245 only; version 11.1.2253 only; version 11.1.2260 only; version 11.1.2261 only; version 11.1.2262 only
  • Avast Pro Antivirus: version 11.1.2241 only; version 11.1.2245 only; version 11.1.2253 only; version 11.1.2260 only; version 11.1.2261 only; version 11.1.2262 only

Published 2016-11-03. Last modified 2026-06-17.