Impact
The vulnerability resides in ClamAV’s PDF file parser, where improper boundary checks allow an attacker to craft a malicious PDF that triggers a buffer over‑read. This can cause the ClamAV scanning process to terminate or corrupt memory, resulting in a denial‑of‑service condition on the victim device. The problem is an out‑of‑bounds buffer read, identified as CWE‑125.
Affected Systems
The affected environment is Cisco Secure Endpoint, which incorporates ClamAV into its antivirus functionality. Specific product versions are not listed, so any instance of Cisco Secure Endpoint that contains the vulnerable ClamAV component may be affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, while the EPSS metric is not available and there is no KEV listing, implying limited public exploit data. An attacker only needs to deliver a carefully crafted PDF to a system that runs the ClamAV scanner; no authentication is required. If successful, the attacker can crash the scanner, leading to a denial of service of the antivirus service and potentially affecting the overall security posture due to reduced protection.
OpenCVE Enrichment