These vulnerabilities are as bad as it gets. They don't require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible.
...
Tuesday's advisory is only the latest to underscore game-over vulnerabilities found in widely available antivirus packages.
https://googleprojectzero.blogspot.com/2016/06/how-to-compromise-enterprise-endpoint.html