Impact
The vulnerability involves an out‑of‑bounds buffer write in ClamAV’s PE file parser. By supplying a crafted PE file to the scanning engine, an unauthenticated, remote attacker can trigger a memory corruption that causes the ClamAV process to terminate. The result is a denial of service; the vendor notes that other impacts may also be possible.
Affected Systems
Cisco Secure Endpoint devices that bundle the ClamAV antivirus engine are affected. No specific product version is listed, so any deployment using the bundled ClamAV in Secure Endpoint is considered vulnerable until the official patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is below 1%, meaning the exploitation probability is low but non‑zero. The vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger it remotely by sending a malicious PE file to the scanner, requiring no privileged access. Once triggered, the ClamAV process crashes, leading to a denial of service on the affected host or service.
OpenCVE Enrichment
Ubuntu USN