Impact
The vulnerability resides in the ClamAV FSG file format parser, where missing boundary checks allow an out‑of‑bounds buffer write when processing FSG files that contain portable executable data. A remote attacker can craft such a file and deliver it to a vulnerable endpoint; the attempted scan will crash the ClamAV process, resulting in a denial‑of‑service condition for the antivirus component and potentially the host system.
Affected Systems
Cisco Secure Endpoint deployments that include the ClamAV FSG parser are affected. No specific product versions are disclosed, so any installation containing the vulnerable parsing routine should be considered at risk until an official update is released.
Risk and Exploitability
The CVSS score of 7.5 indicates a serious impact, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA KEV. An unauthenticated attacker must deliver a malicious FSG file to the target, where the vulnerable parser is activated; the resulting buffer overwrite leads to a process crash and service interruption.
OpenCVE Enrichment
Ubuntu USN