Impact
A flaw in ClamAV’s GPT file format parser allows an attacker to trigger an out‑of‑bounds buffer write during an endian conversion operation. The resulting memory corruption can terminate the ClamAV scanning process, producing a denial‑of‑service condition on the affected device.
Affected Systems
Cisco Secure Endpoint devices that use ClamAV for malware scanning are impacted. No specific vulnerable ClamAV or Cisco Secure Endpoint version numbers are identified in the advisory, so all devices that incorporate the built‑in ClamAV component may be exposed.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely by any unauthenticated user who can provide a malicious GPT file to the scanner. Successful exploitation results in the ClamAV process terminating and a temporary denial of service.
OpenCVE Enrichment