ClamAV OLE2 File Format Parser Vulnerability Could Lead to Denial of Service
CVE-2024-20290
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 7 February 2024
Badges
What is CVE-2024-20290?
A vulnerability exists in the OLE2 file format parser within ClamAV, allowing unauthenticated remote attackers to trigger a denial of service (DoS) on devices utilizing this software. This issue stems from an improper verification of end-of-string values during file scanning processes, leading to potential heap buffer over-reads. By submitting specially crafted files containing OLE2 content for scanning, an attacker could effectively terminate the ClamAV scanning service, which results in a DoS condition while simultaneously consuming the system's available resources. Immediate attention to affected versions is crucial to ensure operational integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Endpoint 6.0.9
Cisco Secure Endpoint 6.0.7
Cisco Secure Endpoint 6.1.5
News Articles
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by securityonline.info
Vulnerability published
Vulnerability Reserved