Description
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ClamAV’s InstallShield parser mishandles temporary storage when processing malformed files. When a crafted InstallShield file is scanned, the parser can allocate excessive resources, causing the scanning process to crash and temporarily deplete system memory or disk space. The result is a denial‑of‑service that interrupts malware detection on the affected endpoint, potentially allowing other malicious activity to go unnoticed until the scanner is restarted.

Affected Systems

The flaw exists in Cisco Secure Endpoint installations that bundle ClamAV for file scanning. Any deployment with InstallShield file parsing enabled is potentially susceptible, as the advisory does not specify exact ClamAV or Cisco versions. Administrators should identify whether their endpoints include this feature and evaluate exposure accordingly.

Risk and Exploitability

The CVSS base score of 7.5 indicates moderate‑to‑high severity. EPSS below 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote and unauthenticated, relying solely on the delivery of a crafted InstallShield file to the endpoint. Exploitation requires only file parsing, but the resulting denial of service can disrupt continuous protection services until the scanner is restarted or a fix is applied.

Generated by OpenCVE AI on August 1, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Cisco Secure Endpoint update that contains the fix for the ClamAV InstallShield parser as soon as it is released.
  • If a patch is not available, temporarily disable InstallShield file scanning or quarantine such files to prevent the vulnerability from being triggered.
  • Limit the temporary directory quota or set resource limits for ClamAV to reduce resource consumption until a fix is deployed.
  • Continuously monitor the ClamAV scanner for abnormal restarts or unusually high temporary file usage and configure alerts to detect exploitation attempts.

Generated by OpenCVE AI on August 1, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8517-1 ClamAV vulnerabilities
History

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Title ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Cisco Secure Endpoint
Clamav Clamav
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-07-01T17:25:08.850Z

Reserved: 2025-10-08T11:59:15.398Z

Link: CVE-2026-20216

cve-icon Vulnrichment

Updated: 2026-07-01T17:21:01.905Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-01T17:16:29.973

Modified: 2026-07-09T18:09:19.380

Link: CVE-2026-20216

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-01T16:27:51Z

Links: CVE-2026-20216 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:00:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling