Impact
The vulnerability is an out‑of‑bounds memory read that occurs in the WithSecure Atlant antivirus engine when it processes a document file. This flaw leads to a crash of the engine, causing a denial of service for users or systems relying on the antivirus for continuous protection. It is classified as CWE‑125, an out‑of‑bounds read weakness.
Affected Systems
WithSecure Atlant products that use the Capricorn engine version preceding the 2025‑01‑20_02 release are affected. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and the EPSS score of 0.00332 indicates extremely low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector appears to be remote, requiring an attacker to supply a crafted document file to the antivirus engine. If successful, the attack will cause an engine crash and availability loss, but no data compromise or remote code execution is disclosed.
OpenCVE Enrichment