Threat Advisory

Multiple ClamAV Flaws Cause Denial of Service Condition

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Summary

Multiple high-severity vulnerabilities have been identified in ClamAV file-format parsers used by affected Cisco Secure Endpoint products. The flaws involve out-of-bounds writes and reads, memory corruption, double-free conditions, and integer overflow during the scanning of crafted ZIP, PESpin, GPT, PDF, Mach-O, and XAR files. Successful exploitation could allow unauthenticated remote attackers to terminate the ClamAV scanning process and cause denial-of-service conditions.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Summary

Multiple high-severity vulnerabilities have been identified in ClamAV file-format parsers used by affected Cisco Secure Endpoint products. The flaws involve out-of-bounds writes and reads, memory corruption, double-free conditions, and integer overflow during the scanning of crafted ZIP, PESpin, GPT, PDF, Mach-O, and XAR files. Successful exploitation could allow unauthenticated remote attackers to terminate the ClamAV scanning process and cause denial-of-service conditions.[emaillocker id="1283"]

• CVE-2026-20337 with a CVSS score of 7.5 – An out-of-bounds write in the ClamAV ZIP parser can be triggered by a crafted ZIP file, causing the scanning process to terminate.

• CVE-2026-20338 with a CVSS score of 7.5 – Improper memory handling in the ZIP parser can result in a double-free condition and denial of service.

• CVE-2026-20339 with a CVSS score of 7.5 – An integer overflow in the PESpin parser can cause memory corruption and potentially terminate the ClamAV scanning process.

• CVE-2026-20345 with a CVSS score of 7.5 – Improper endian conversion handling in the GPT parser can result in an out-of-bounds buffer write and denial of service.

• CVE-2026-20346 with a CVSS score of 7.5 – Improper boundary checks in the PDF parser can cause an out-of-bounds buffer read and terminate the scanning process.

• CVE-2026-20347 with a CVSS score of 7.5 – Improper boundary checks in the Mach-O parser can result in an out-of-bounds buffer read and denial of service.

• CVE-2026-20348 with a CVSS score of 7.5 – Improper boundary checks in the XAR parser can cause memory corruption and terminate the ClamAV scanning process.

These vulnerabilities present a high risk to affected Cisco Secure Endpoint deployments, particularly Windows-based systems where ClamAV operates in a privileged security context. Proof-of-concept exploit code is available for CVE-2026-20337 and CVE-2026-20338, although no malicious exploitation is currently known. Organizations should apply the available Cisco security updates, as no workarounds are available.

RECOMMENDATION:

We recommend you to upgrade affected Cisco Secure Endpoint products to Secure Endpoint Connector for Windows 8.6.2+, Linux 1.29.0+, Mac 1.27.2+, and Secure Endpoint Private Cloud 4.2.8+; ClamAV fixes are included in versions 1.5.3+ and 1.4.5+

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu