ClamAV Flaws Expose Cisco Secure Endpoint to Remote DoS Attacks
Cisco has issued an advisory warning of multiple ClamAV memory-corruption vulnerabilities that could allow unauthenticated remote attackers to disrupt scanning operations on affected Cisco Secure Endpoint Connector installations.
The flaws, disclosed in advisory cisco-sa-clamav-WuuvVd26, affect Windows, Linux, and macOS endpoints that use the ClamAV engine to inspect files. Successful exploitation can terminate the ClamAV scanning process.
Cisco assigned affected Windows connectors a High impact rating and a CVSS base score of 7.5. The higher Windows rating reflects the privileged context in which the scanning process executes.
Administrators should prioritize Windows systems, confirm that automatic connector updates are enabled where appropriate, and rapidly deploy fixed releases as they become available. Until then, organizations can reduce exposure by applying strict controls to untrusted files.