Impact
A flaw in ClamAV’s ALZ file parser causes out‑of‑bounds buffer writes due to missing boundary checks for ALZ content. An attacker can craft a malicious ALZ file and submit it for scanning, resulting in memory corruption that terminates the ClamAV process and produces a denial of service. The CVE description notes that further impacts are possible but only memory corruption is demonstrated.
Affected Systems
Cisco Secure Endpoint uses ClamAV for malware scanning, and the vulnerability originates from the ALZ parser component of ClamAV. All installations of Cisco Secure Endpoint that include the unpatched ClamAV ALZ parser are susceptible; no specific version range is supplied, so any deployments employing that parser are at risk.
Risk and Exploitability
The CVSS score of 7.5 reflects the severity of the memory‑corruption attack, while the EPSS score of < 1 % indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and unauthenticated: a malicious actor can deliver a crafted ALZ file to a vulnerable system, trigger the buffer overwrite, and cause ClamAV to crash, resulting in a service interruption.
OpenCVE Enrichment
Ubuntu USN