Critical RCE Vulnerability Discovered in ClamAV Open Source Antivirus Software

Share:

Cisco has rolled out security updates to address a critical flaw reported in the ClamAV open source antivirus engine that could lead to remote code execution on susceptible devices.

Tracked as CVE-2023-20032 (CVSS score: 9.8), the issue relates to a case of remote code execution residing in the HFS+ file parser component.

The flaw affects versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier. Google security engineer Simon Scannell has been credited with discovering and reporting the bug.

“This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write,” Cisco Talos said in an advisory. “An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device.”

Successful exploitation of the weakness could enable an adversary to run arbitrary code with the same privileges as that of the ClamAV scanning process, or crash the process, resulting in a denial-of-service (DoS) condition.

The networking equipment said the following products are vulnerable –

  • Secure Endpoint, formerly Advanced Malware Protection (AMP) for Endpoints (Windows, macOS, and Linux)
  • Secure Endpoint Private Cloud, and
  • Secure Web Appliance, formerly Web Security Appliance

It further confirmed that the vulnerability does not impact Secure Email Gateway (formerly Email Security Appliance) and Secure Email and Web Manager (formerly Security Management Appliance) products.

Also patched by Cisco is a remote information leak vulnerability in ClamAV’s DMG file parser (CVE-2023-20052, CVSS score: 5.3) that could be exploited by an unauthenticated, remote attacker.

“This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection,” Cisco noted. “An attacker could exploit this vulnerability by submitting a crafted DMG file to be scanned by ClamAV on an affected device.”

It’s worth pointing out that CVE-2023-20052 does not affect Cisco Secure Web Appliance. That said, both vulnerabilities have been addressed in ClamAV versions 0.103.8, 0.105.2, and 1.0.1.

Cisco separately also resolved a denial-of-service (DoS) vulnerability impacting Cisco Nexus Dashboard (CVE-2023-20014, CVSS score: 7.5) and two other privilege escalation and command injection flaws in Email Security Appliance (ESA) and Secure Email and Web Manager (CVE-2023-20009 and CVE-2023-20075, CVSS scores: 6.5).

 

(c) Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:11 am, Jul 14, 2025
weather icon 20°C
L: 19° | H: 22°
overcast clouds
Humidity: 74 %
Pressure: 1011 mb
Wind: 8 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 88%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:59 am
Sunset: 9:12 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 22°°C 0 mm 0% 15 mph 75 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 21°°C 1 mm 100% 19 mph 84 % 1016 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
15° | 27°°C 0.2 mm 20% 13 mph 85 % 1017 mb 0 mm/h
Thu Jul 17 10:00 pm
weather icon
18° | 27°°C 0.76 mm 76% 10 mph 91 % 1017 mb 0 mm/h
Fri Jul 18 10:00 pm
weather icon
18° | 31°°C 0.53 mm 53% 5 mph 93 % 1015 mb 0 mm/h
Today 4:00 am
weather icon
16° | 19°°C 0 mm 0% 8 mph 72 % 1011 mb 0 mm/h
Today 7:00 am
weather icon
17° | 18°°C 0 mm 0% 10 mph 75 % 1011 mb 0 mm/h
Today 10:00 am
weather icon
21° | 21°°C 0 mm 0% 12 mph 54 % 1012 mb 0 mm/h
Today 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 14 mph 36 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 25°°C 0 mm 0% 15 mph 42 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 33 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 9 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 9 mph 61 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,807.44
1.45%
Ethereum(ETH)
€2,541.70
1.08%
XRP(XRP)
€2.42
3.74%
Tether(USDT)
€0.85
0.01%
Solana(SOL)
€137.65
0.26%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.169780
0.75%
Shiba Inu(SHIB)
€0.000011
1.13%
Pepe(PEPE)
€0.000010
0.45%
Peanut the Squirrel(PNUT)
€0.244320
5.81%
Scroll to Top