Junglewise Threat Intelligence

CVE-2026-20244: Cisco ClamAV integer overflow in DMG file parser

CVE-2026-20244 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Cisco Systems, Inc. Secure Endpoint Connector for Mac, Cisco Systems, Inc. Secure Endpoint Connector for Windows, Cisco Systems, Inc. ClamAV, Cisco Systems, Inc. Secure Endpoint Connector for Linux.

Executive brief

ClamAV is an open-source antivirus engine used to scan files for malicious content. A vulnerability in how it processes Apple Disk Image (DMG) files could allow an attacker to crash the scanning service by sending a specially crafted file. This results in a denial-of-service condition where the system can no longer scan new files for threats, and on Windows systems, it may require a manual reboot to restore operations.

Technical details

This vulnerability (CWE-120) exists in the DMG file format parser of ClamAV due to improper boundary checks during file scanning. Specifically, the flaw can lead to an integer overflow on 32-bit platforms when processing crafted DMG content, resulting in memory corruption. An unauthenticated remote attacker can exploit this by providing a malicious DMG file to be scanned, causing the ClamAV process to terminate. While primarily a DoS risk, Cisco notes that memory corruption could potentially lead to other impacts, though modern 64-bit protections mitigate code execution risks. The vulnerability is patched in ClamAV and integrated Cisco Secure Endpoint products (e.g., Windows Connector 8.6.2).

Affected products

  • Cisco Systems, Inc. ClamAV
  • Cisco Systems, Inc. Secure Endpoint Connector for Windows Prior to 8.6.2
  • Cisco Systems, Inc. Secure Endpoint Connector for Linux Prior to 1.29.0
  • Cisco Systems, Inc. Secure Endpoint Connector for Mac Prior to 1.27.2

Timeline

  • 2026-07-01: advisory: Cisco published the security advisory.
  • 2026-07-01: patched: Fixed versions released for Cisco Secure Endpoint products.

References