CVE-2025-20128

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 22, 2025
CWE ID 122
CWE ID 120

Summary

CVE-2025-20128 is a newly disclosed vulnerability that affects the Object Linking and Embedding 2 (OLE2) decryption routine in ClamAV. An unauthenticated, remote attacker can cause a denial of service (DoS) condition by exploiting an integer underflow in a bounds check, leading to a heap buffer overflow read. Submitting a specially crafted file containing OLE2 content to an affected ClamAV installation can trigger this vulnerability, causing the scanning process to terminate and resulting in a DoS condition. No workarounds are available, and Cisco has released software updates to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Secure Endpoint

Affected Vendors

  • Cisco Systems Inc