ClamAV Memory Corruption Bugs Expose Cisco Secure Endpoint to Remote DoS Attacks
Brief
Cisco has warned that multiple ClamAV memory-corruption vulnerabilities can allow unauthenticated remote attackers to disrupt scanning operations on affected Cisco Secure Endpoint Connector installations.
The flaws, disclosed in advisory cisco-sa-clamav-WuuvVd26, affect Windows, Linux, and macOS endpoints that use the ClamAV engine to inspect files. Successful exploitation can terminate the ClamAV scanning process.
Cisco assigned affected Windows connectors a High impact rating and a CVSS base score of 7.
- The higher Windows rating reflects the privileged context in which the scanning process executes.
ClamAV Memory Corruption Bugs
Linux and macOS connectors received Medium ratings because their scanning processes run with lower privileges. Risk remains material across platforms.
Attackers need not authenticate or persuade a user to open a file to exploit the affected parser.
