Impact
A weakness in the zip archive parser of ClamAV causes a memory double‑free when a crafted zip file is processed during scanning. The resulting crash terminates the ClamAV scanning process, causing a denial of service that affects the entire scanning infrastructure of the host. An attacker can exploit this flaw remotely without authentication by submitting a malicious zip file to any endpoint that invokes the ClamAV engine.
Affected Systems
This vulnerability impacts Cisco Secure Endpoint products that embed the ClamAV engine for threat detection. The advisory does not specify which product or software versions are affected, so any installation that relies on the vulnerable ClamAV component is at risk until the vendor publishes a fix.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation records at present. Nevertheless, the attack can be performed with remote, unauthenticated access, and a successful exploit will unconditionally bring down the scanning service, potentially exposing the system to further attacks or impairing security monitoring. Because the failure involves a double‑free, it is unlikely to provide privilege escalation or data exposure, but it does create an operational impact that could be critical in high‑security environments.
OpenCVE Enrichment