Junglewise Threat Intelligence

CVE-2026-20217: Cisco ClamAV out-of-bounds write in PESpin file parser

CVE-2026-20217 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Cisco Secure Endpoint Connector for Mac, Cisco Secure Endpoint Connector for Linux, Cisco Secure Endpoint Connector for Windows, Cisco ClamAV. Vendors: Cisco.

Executive brief

A vulnerability in the ClamAV antivirus engine, used in various Cisco security products, could allow an attacker to crash the scanning service. By sending a specially crafted file to be scanned, an attacker can cause the software to stop functioning, creating a denial-of-service condition. On Windows systems, this is particularly severe as the scanning process runs with high privileges and may require a manual reboot to recover.

Technical details

A memory corruption vulnerability exists in the PESpin file format parser of ClamAV due to improper boundary checks during file scanning. This flaw allows an unauthenticated, remote attacker to trigger an out-of-bounds buffer write by submitting a specially crafted PESpin file. A successful exploit can lead to the termination of the ClamAV scanning process, resulting in a denial-of-service (DoS) condition. While primarily a DoS risk, the memory corruption could potentially lead to other impacts, though Cisco notes that modern memory protections make remote code execution difficult. Patches have been released for affected Cisco Secure Endpoint Connectors.

Affected products

  • Cisco Secure Endpoint Connector for Windows Before 8.6.2
  • Cisco Secure Endpoint Connector for Linux Before 1.29.0
  • Cisco Secure Endpoint Connector for Mac Before 1.27.2
  • Cisco ClamAV All versions prior to fixed releases

Timeline

  • 2026-07-01: disclosed: Initial advisory publication by Cisco and NVD
  • 2026-07-01: patched: Fixed versions released for Cisco Secure Endpoint products

References

Related threats