Impact
ClamAV’s InstallShield parser mishandles temporary storage when processing malformed files. An attacker can trigger the parser to allocate excessive resources, causing the scanning process to crash and deplete system memory or disk space temporarily. The result is a denial of service that interrupts malware detection on the affected endpoint, potentially allowing other malicious activity to go unnoticed until the scanner is restarted.
Affected Systems
The flaw exists in Cisco Secure Endpoint installations that bundle ClamAV for file scanning. Any deployment that enables InstallShield file parsing is susceptible, regardless of the specific ClamAV or Cisco software version, because the advisory does not list affected releases. Organizations must examine whether their endpoints include this feature and assess exposure.
Risk and Exploitability
The CVSS base score of 7.5 indicates moderate-to-high severity. EPSS below 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote and unauthenticated, relying solely on the delivery of a crafted InstallShield file to the endpoint. While exploitation requires only file parsing, the resulting denial of service can disrupt continuous protection services until the scanner is restarted or a patch is applied.
OpenCVE Enrichment
Ubuntu USN