Executive brief
A vulnerability in the ClamAV antivirus engine could allow an attacker to crash the scanning service by providing a specially crafted InstallShield file. This affects security products that use ClamAV to scan files, such as Cisco Secure Endpoint. An exploit would stop the system from scanning for threats and could temporarily exhaust system resources, leading to a denial-of-service condition.
Technical details
A vulnerability exists in the InstallShield file format parser of ClamAV (CWE-770) due to improper handling of temporary resources during file scanning. An unauthenticated remote attacker can exploit this by submitting a crafted InstallShield file for scanning. Successful exploitation results in the termination of the ClamAV scanning process and temporary consumption of system resources, leading to a denial-of-service (DoS) condition. On Windows-based platforms, this is rated as High severity because the process runs in a privileged context, whereas on Linux and Mac, it is rated as Medium. Cisco has released updates for affected Secure Endpoint products to address this issue.
Affected products
- Cisco ClamAV
- Cisco Secure Endpoint Connector for Windows Prior to 8.6.2
- Cisco Secure Endpoint Connector for Linux Prior to 1.29.0
- Cisco Secure Endpoint Connector for Mac Prior to 1.27.2
Timeline
- 2026-07-01: disclosed
- 2026-07-01: patched
- 2026-07-01: advisory