Impact
ClamAV’s XAR file format parser implements an improper boundary check that can corrupt memory when scanning crafted XAR content. The resulting failure can cause the ClamAV process to terminate, leading to a denial‑of‑service condition on the affected system. The weakness is classified as CWE‑120 (Buffer Overflow). The vulnerability does not allow direct code execution but can disrupt service availability and potentially enable additional compromises if the system is otherwise compromised. The impact is limited to the ClamAV scanning engine and does not directly affect user credentials or data integrity. The vulnerability is remote and requires only an unauthenticated attacker to submit a malicious file for scanning.
Affected Systems
The vendor product impacted is Cisco Secure Endpoint, which incorporates ClamAV for virus scanning. Specific product version information is not given in the advisory, so all installations that embed the vulnerable ClamAV component should be evaluated.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. Its EPSS score is not available, so current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, but the potential to cause service interruption makes it relevant for continuous monitoring. The attack path is straightforward: an unauthenticated attacker sends a crafted XAR file to a device running Cisco Secure Endpoint, causing a memory corruption that terminates the ClamAV scanning process.
OpenCVE Enrichment