Impact
ClamAV’s InstallShield parser mishandles temporary storage when processing malformed files. When a crafted InstallShield file is scanned, the parser can allocate excessive resources, causing the scanning process to crash and temporarily deplete system memory or disk space. The result is a denial‑of‑service that interrupts malware detection on the affected endpoint, potentially allowing other malicious activity to go unnoticed until the scanner is restarted.
Affected Systems
The flaw exists in Cisco Secure Endpoint installations that bundle ClamAV for file scanning. Any deployment with InstallShield file parsing enabled is potentially susceptible, as the advisory does not specify exact ClamAV or Cisco versions. Administrators should identify whether their endpoints include this feature and evaluate exposure accordingly.
Risk and Exploitability
The CVSS base score of 7.5 indicates moderate‑to‑high severity. EPSS below 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote and unauthenticated, relying solely on the delivery of a crafted InstallShield file to the endpoint. Exploitation requires only file parsing, but the resulting denial of service can disrupt continuous protection services until the scanner is restarted or a fix is applied.
OpenCVE Enrichment
Ubuntu USN