Code Defence Cyber security

Cisco warns of high-severity ClamAV parser vulnerabilities with public proof of concept exploit code

Security advisories published by enterprise security maintainers warn that widely deployed antimalware scanning engines contain multiple high-severity file parsing vulnerabilities. Threat research confirms public proof of concept exploit code is actively circulating for defects that allow unauthenticated remote actors to cause denial-of-service conditions or execute path traversal operations.

The security issues impact Cisco Secure Endpoint Connector products across Windows, macOS, and Linux platforms that integrate the open-source ClamAV malware scanning engine. Tracked under CVE-2026-20337 through CVE-2026-20348, the defects stem from improper bounds checking and path verification within parsers handling ZIP, GPT, PESpin, PDF, Mach-O, and XAR archive formats. An attacker delivering malformed archive files via email or automated file gateways can trigger infinite loops, crashing the endpoint security daemon or writing files into unauthorized system directories.

Subverting local antimalware engines compromises host detection capabilities across enterprise endpoints. When scanning subroutines are forced into crash loops or denial-of-service states, malicious files can traverse security gateways without inspection, increasing host vulnerability to secondary execution vectors.

– Upgrade ClamAV scanning engine modules to version 1.5.4 or later immediately across all endpoint deployments.

– Apply current security maintenance updates provided by Cisco for Secure Endpoint Connector products.

– Configure email security gateways to quarantine compressed archives with malformed header structures.

– Restrict unprivileged write permissions on temporary scanning directories to prevent path traversal exploitation.

Endpoint security scanning resilience relies on continuous parser input validation to guarantee that malware inspection engines remain operational and insulated from malicious archive payloads. #CodeDefence #Cisco #ClamAV #Antivirus #AppSec #PathTraversal #EndpointSecurity #PatchManagement
/

Scroll to Top