ClamAV Flaw Exposes Endpoints to Remote Crash Attacks
A critical vulnerability in Cisco's ClamAV software has put organizations on high alert as attackers could crash antivirus scanning engines using malicious files.
The seven newly disclosed vulnerabilities, confirmed by Cisco, allow an attacker to interrupt the ClamAV scanning process and trigger a denial-of-service condition, effectively knocking out malware detection at the moment it's needed most. The flaws affect Cisco Secure Endpoint Connector across all three major operating systems: Windows, Linux, and macOS.
The affected parsers span a wide range of file types commonly encountered in enterprise environments, including ZIP, PDF, disk images, and executable files. Two of the seven vulnerabilities have already been exploited with publicly available proof-of-concept code, raising the urgency for defenders to patch their systems as soon as possible.