Impact
A flaw in the Mach‑O file format parser of ClamAV can lead to a denial‑of‑service condition when a crafted Mach‑O file is scanned. The vulnerability stems from missing boundary checks that cause an out‑of‑bounds memory read (CWE‑125). An attacker who can supply a malicious file to the ClamAV scanning process can trigger the crash, terminating the service and making the affected system unavailable for legitimate scans.
Affected Systems
The vulnerability affects devices running Cisco Secure Endpoint that include the ClamAV engine. Specific version information is not provided in the advisory, but the issue is present in all versions of the included ClamAV library that lack the patch.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity threat. The EPSS score is not available, but the fact that the problem is unauthenticated and remote means an attacker could potentially exploit it from the network. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a crafted Mach‑O file to the machine; no additional prerequisites or privileged access are required beyond the ability to submit a file for scanning.
OpenCVE Enrichment