Impact
The vulnerability involves an out-of-bounds buffer write in ClamAV’s PE file parser. By supplying a crafted PE file to the scanning engine, an unauthenticated, remote attacker can trigger a memory corruption that causes the ClamAV process to terminate. other impacts may also be possible.
Affected Systems
Cisco Secure Endpoint devices that bundle the ClamAV antivirus engine are affected. No specific product version in Secure Endpoint is considered vulnerable until the official patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is below 1%, meaning the exploitation probability is low but non-zero. The vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger it remotely by sending a malicious PE file to the scanner, requiring no privileged access. Once triggered, the ClamAV process crashes, leading to a denial of service on the affected host or service.
OpenCVE Enrichment
Ubuntu USN