Impact
The vulnerability arises from improper boundary checks in the FSG file format parser of ClamAV, leading to an out-of-bounds buffer write when a malicious FSG file containing portable executable content is scanned. An attacker can submit such a crafted file remotely to trigger this flaw, causing the ClamAV scanning process to crash and resulting in a denial-of-service condition. The description indicates that the memory corruption may allow further exploitation, but no additional impacts are documented.
Affected Systems
Cisco Secure Endpoint deployments that include the vulnerable ClamAV FSG parser are affected. Specific version details have not been published; therefore any installation of the endpoint software that incorporates the FSG parsing routine could be at risk.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote and unauthenticated, with the attacker providing malicious FSG files for scanning. Successful exploitation results in a crash of the scanning process, producing a denial-of-service for the host system and the antivirus application.
OpenCVE Enrichment
Ubuntu USN