Description
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ClamAV’s InstallShield parser mishandles temporary storage when processing malformed files. An attacker can trigger the parser to allocate excessive resources, causing the scanning process to crash and deplete system memory or disk space temporarily. The result is a denial of service that interrupts malware detection on the affected endpoint, potentially allowing other malicious activity to go unnoticed until the scanner is restarted.

Affected Systems

The flaw exists in Cisco Secure Endpoint installations that bundle ClamAV for file scanning. Any deployment that enables InstallShield file parsing is susceptible, regardless of the specific ClamAV or Cisco software version, because the advisory does not list affected releases. Organizations must examine whether their endpoints include this feature and assess exposure.

Risk and Exploitability

The CVSS base score of 7.5 indicates moderate-to-high severity. EPSS below 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote and unauthenticated, relying solely on the delivery of a crafted InstallShield file to the endpoint. While exploitation requires only file parsing, the resulting denial of service can disrupt continuous protection services until the scanner is restarted or a patch is applied.

Generated by OpenCVE AI on July 21, 2026 at 13:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Cisco Secure Endpoint update that contains the ClamAV InstallShield parser fix as soon as it becomes available.
  • If a patch is not yet released, disable InstallShield file scanning or quarantine such files until a definitive update is applied.
  • Restrict the temporary directory quota used by ClamAV to limit resource consumption until a fix is deployed.
  • Monitor the ClamAV scanner for abnormal restarts or unusually high temporary file usage and configure alerts to detect exploitation attempts early.

Generated by OpenCVE AI on July 21, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8517-1 ClamAV vulnerabilities
History

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Title ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-07-01T17:25:08.850Z

Reserved: 2025-10-08T11:59:15.398Z

Link: CVE-2026-20216

cve-icon Vulnrichment

Updated: 2026-07-01T17:21:01.905Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-01T16:27:51Z

Links: CVE-2026-20216 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:00:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling