Home Content News ClamAV Hit By Seven Vulnerabilities, With Public PoCs Available For Two Flaws

ClamAV Hit By Seven Vulnerabilities, With Public PoCs Available For Two Flaws

0
1
Cisco logo
Cisco logo

Seven vulnerabilities in open-source ClamAV affect Cisco Secure Endpoint products, with public PoCs for two flaws raising the urgency for enterprise users to patch.

Seven high-severity vulnerabilities in the open-source ClamAV malware detection engine affect Cisco Secure Endpoint Connector products on Windows, macOS, and Linux, potentially allowing remote, unauthenticated attackers to trigger denial-of-service (DoS) conditions.

ClamAV is an open-source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. The vulnerabilities are tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, with public proof-of-concept (PoC) code available for CVE-2026-20337 and CVE-2026-20338.

The flaws affect ClamAV parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats. ClamAV 1.5.4 patches all seven vulnerabilities and also addresses a WinRAR path traversal flaw on Windows that could lead to arbitrary code execution.

Cisco says no workaround exists, with security updates for Secure Endpoint Connector products being rolled out in August. The vulnerabilities pose a high risk on Windows “because those platforms run the ClamAV scanning process in a privileged security context.” On macOS and Linux, where the scanning process runs with lower privileges, the risk is rated medium.

Secure Endpoint Private Cloud is not affected, but customers using affected Connector software are advised to push patches to endpoints. Relevant Private Cloud releases are 4.2.8 and later. Cisco says it is not aware of exploitation in the wild.

LEAVE A REPLY

Please enter your comment!
Please enter your name here