Impact
The flaw exists in the 7z file format parser of ClamAV; boundary checks for content in 7z archives are missing, allowing an attacker to craft a file that triggers an out-of-bounds buffer write during scanning. This is a CWE‑120 buffer overflow vulnerability. The resulting memory corruption can terminate the ClamAV scanning process, creating a denial‑of‑service condition on the affected device and potentially enabling broader impact if the attacker later gains additional access.
Affected Systems
Cisco Secure Endpoint deployments that embed ClamAV and rely on its 7z parsing capability are vulnerable. No specific ClamAV or Cisco Secure Endpoint version information is disclosed, so any installation that includes the 7z parser may be at risk. The impact applies to devices that scan files received through network traffic, VPNs, or local storage.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high risk to service availability, while the EPSS score of less than 1% suggests a currently very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An unauthenticated remote attacker can send a malicious 7z file via any channel that delivers content to the ClamAV scanner, triggering the out‑of‑bounds write and causing the scanner to crash. Exploitation requires no special privileges and can be performed from outside the network, making it straightforward if the scanner processes untrusted archives.
OpenCVE Enrichment
Ubuntu USN