Description
Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.
Published: 2026-09-14
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds memory read that occurs in the WithSecure Atlant antivirus engine when it processes a document file. This flaw leads to a crash of the engine, causing a denial of service for users or systems relying on the antivirus for continuous protection. It is classified as CWE‑125, an out‑of‑bounds read weakness.

Affected Systems

WithSecure Atlant products that use the Capricorn engine version preceding the 2025‑01‑20_02 release are affected. No other vendors or product lines are listed as impacted.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and the EPSS score of 0.00332 indicates extremely low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector appears to be remote, requiring an attacker to supply a crafted document file to the antivirus engine. If successful, the attack will cause an engine crash and availability loss, but no data compromise or remote code execution is disclosed.

Generated by OpenCVE AI on September 15, 2026 at 16:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to WithSecure Atlant version 2025‑01‑20_02 or later to apply the fix for the out‑of‑bounds read.
  • If an immediate upgrade is not possible, disable or quarantine processing of unknown or suspicious document files by configuring the antivirus engine to reject or isolate such files instead of executing the scan.
  • Monitor antivirus logs and system stability for crashes or restarts that may indicate exploitation attempts and document any incidents for further investigation.

Generated by OpenCVE AI on September 15, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Leading to Remote Denial of Service in WithSecure Atlant Antivirus Engine

Mon, 14 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Leading to Remote Denial of Service in WithSecure Atlant Antivirus Engine

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.
First Time appeared Withsecure
Withsecure atlant
Weaknesses CWE-125
CPEs cpe:2.3:a:withsecure:atlant:*:*:*:*:*:*:*:*
Vendors & Products Withsecure
Withsecure atlant
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Withsecure Atlant
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:12:39.871Z

Reserved: 2025-02-14T00:00:00.000Z

Link: CVE-2025-26790

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:27.179Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:16.267

Modified: 2026-09-22T20:00:03.713

Link: CVE-2025-26790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses