Executive brief
ClamAV is an open-source antivirus engine used to scan files for malicious content. A vulnerability in how it processes Apple Disk Image (DMG) files could allow an attacker to crash the scanning service by sending a specially crafted file. This results in a denial-of-service condition where the system can no longer scan new files for threats, and on Windows systems, it may require a manual reboot to restore operations.
Technical details
This vulnerability (CWE-120) exists in the DMG file format parser of ClamAV due to improper boundary checks during file scanning. Specifically, the flaw can lead to an integer overflow on 32-bit platforms when processing crafted DMG content, resulting in memory corruption. An unauthenticated remote attacker can exploit this by providing a malicious DMG file to be scanned, causing the ClamAV process to terminate. While primarily a DoS risk, Cisco notes that memory corruption could potentially lead to other impacts, though modern 64-bit protections mitigate code execution risks. The vulnerability is patched in ClamAV and integrated Cisco Secure Endpoint products (e.g., Windows Connector 8.6.2).
Affected products
- Cisco Systems, Inc. ClamAV
- Cisco Systems, Inc. Secure Endpoint Connector for Windows Prior to 8.6.2
- Cisco Systems, Inc. Secure Endpoint Connector for Linux Prior to 1.29.0
- Cisco Systems, Inc. Secure Endpoint Connector for Mac Prior to 1.27.2
Timeline
- 2026-07-01: advisory: Cisco published the security advisory.
- 2026-07-01: patched: Fixed versions released for Cisco Secure Endpoint products.