CVE-2025-20128
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-20128 is a newly disclosed vulnerability that affects the Object Linking and Embedding 2 (OLE2) decryption routine in ClamAV. An unauthenticated, remote attacker can cause a denial of service (DoS) condition by exploiting an integer underflow in a bounds check, leading to a heap buffer overflow read. Submitting a specially crafted file containing OLE2 content to an affected ClamAV installation can trigger this vulnerability, causing the scanning process to terminate and resulting in a DoS condition. No workarounds are available, and Cisco has released software updates to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Secure Endpoint
Affected Vendors
- Cisco Systems Inc