Search/clamav
Vendor

clamav

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
clamav
Connections
11 relationships
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. As Cisco explained in a Friday advisory, the two vulnerabilities are due to improper boundary checks and memory handling, respectively, and can be exploited by unauthenticated, remote attackers. The company's Product Security Incident Response Team (PSIRT) added that proof-of-concept (PoC) exploit code is already publicly available, but said that it has no evidence the flaws have been exploited in the wild. "An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software," it said. "The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in CVE-2026-20337 and CVE-2026-20338." Cisco added that the flaws' security impact is high only for Windows platforms since they're the only ones that "run the ClamAV scanning process in a privileged security context." These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4 released on August 7. While there are no workarounds for CVE-2026-20337 and CVE-2026-20338, the company plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac. On Friday, Cisco patched five other ClamAV security flaws that can also be exploited to trigger denial-of-service conditions by submitting malicious XAR, Mach-O, PDF, GPT, and PESpin files for scanning. It patched another ClamAV DoS vulnerability with PoC exploit code in January 2025, warning that attackers could abuse it to terminate the ClamAV antivirus scanner, preventing or delaying further scanning operations. Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has tagged 95 Cisco vulnerabilities as actively exploited in attacks, six of them abused in ransomware attacks. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 11, 2026extracted
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. The security defects, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, were discovered in ClamAV’s parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats. Patches for the bugs were included in ClamAV version 1.5.4, which also includes the patch for a path traversal weakness in WinRAR for Windows that could lead to arbitrary code execution. Shortly after ClamAV rolled out the fixes, Cisco published an advisory warning that PoC code targeting CVE-2026-20337 and CVE-2026-20338 exists. According to the company, no workaround exists for any of the vulnerabilities and security updates addressing them will be rolled out in August for all Secure Endpoint Connector products. The security defects, Cisco says, pose a high risk to Windows users, “because those platforms run the ClamAV scanning process in a privileged security context.” On macOS and Linux, the flaws pose a medium-severity risk, as the ClamAV scanning process runs on them with lower privileges. Secure Endpoint Private Cloud is not affected, but the Secure Endpoint Connector software is impacted, and customers are advised to push the available patches (included in Secure Endpoint Private Cloud releases 4.2.8 and later) from the cloud to their endpoints. The company says it is not aware of any of these vulnerabilities being exploited in the wild. Related: Metabase Patches Vulnerability Exploited as Zero-Day Related: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Related: Critical Paperclip Flaw Allowed Admin Access, Code Execution Related: Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
securityweek.comAug 10, 2026extracted
Risolte vulnerabilità in ClamAV
Risolte vulnerabilità in ClamAV Alert AL01/260810/CSIRT-ITA Sintesi Aggiornamenti di sicurezza Cisco sanano 7 vulnerabilità con gravità "alta" presenti in ClamAV, software open source per l'analisi antivirus. Tra queste si evidenziano le CVE-2026-20337 e CVE-2026-20338 per le quali il vendor conferma la presenza di Proof of Concept (PoC) disponibili in rete. Tali vulnerabilità, qualora sfruttate potrebbero compromettere la disponibilità del servizio sui sistemi interessati, interrompendo le operazioni di scansione. Tipologia Denial of Service Descrizione e potenziali impatti Nel dettaglio, le vulnerabilità identificate tramite le CVE-2026-20337 e CVE-2026-20338, di tipo "Denial of Service" e con score CVSS 3.x pari a 7.5, interessano il parser degli archivi ZIP in ClamAV. Dovute a un'errata convalida dei parametri di input durante la scansione dei file ZIP, tali vulnerabilità potrebbero permettere, a un attaccante remoto non autenticato, la possibilità di sottomettere archivi opportunamente predisposti al fine di compromettere la disponibilità del servizio sui sistemi interessati. Prodotti e/o versioni affette Cisco Secure Endpoint Connector per Windows, Linux e Mac, versioni precedenti alla build di Agosto 2026 Private Cloud 4.2.x, versioni precedenti alla 4.2.8 ClamAV 1.5.x, versioni precedenti alla 1.5.4 1.4.x, versioni precedenti alla 1.4.6 Azioni di mitigazione Si raccomanda di aggiornare i prodotti vulnerabili seguendo le istruzioni fornite dal vendor riportate nel bollettino di sicurezza disponibile al link nella sezione Riferimenti. NB: Le versioni di Secure Endpoint Connector sono in corso di rilascio nell'arco di Agosto 2026. I connettori aggiornati verranno distribuiti direttamente dal portale Cisco Secure Endpoint. Qualora le policy aziendali prevedano l'aggiornamento automatico, i client si aggiorneranno automaticamente non appena la build sarà pubblicata.
acn.gov.itAug 10, 2026extracted
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel. Once installed, the RAT process keeps all of its own traffic on 127.0.0[.]1. External traffic leaves from a legitimate browser process: HTTPS to a Cloudflare developer domain, a STUN request to a Google server, then WebRTC to a Twilio relay. Shell commands execute on the victim host and the output returns along the same path. The design needs a browser it can locate on the machine. Chaos operates as ransomware-as-a-service, confirmed active since February 2025, using vishing and spam email for initial access and double extortion afterward. Michael Szeliga, a Cisco Talos researcher and one of the authors of the analysis, was asked what this changes for defenders and whether other groups will follow. “This continues the shift defenders have already been dealing with, where attackers use legitimate cloud and collaboration services to hide C2 traffic. I expect browser-mediated C2 and similar approaches to become more prevalent, much like what was demonstrated with Praetorian’s TURNt research using Microsoft Teams TURN infrastructure. Threat actors will continue looking for ways to hide inside trusted applications and services, making behavior-based detection increasingly important, especially in ransomware attacks,” Szeliga told Help Net Security. Delivery arrives dressed as a Windows update The operator already has access to the machine when this starts. A curl.exe command pulls an MSI impersonating a Windows update into ProgramData. The attacker then executes it. The URL specifies port 443, the traffic is plain HTTP, and firewall rules that read port numbers with no protocol inspection pass it through. Installation ends with a custom action loading a DLL from inside the installer straight into memory. That DLL is msaRAT. msaRAT hunts for a browser on disk msaRAT checks six fixed locations drawn from environment variables, split between Chrome and Edge, then falls back to a registry lookup that covers Chrome alone. Finding a browser, it launches a fresh process headless, with the remote debugging port enabled and a user-data directory the malware specifies. Finding none, the whole C2 mechanism sits idle. The RAT connects to that debugging port over the loopback address, opens a tab in the instance it started, and turns off Content Security Policy for the page. It registers callbacks the browser’s JavaScript uses to report back, then injects JavaScript stored in plaintext inside the binary. What the network sees is a browser doing WebRTC The injected JavaScript pulls connection configuration from a Cloudflare Workers endpoint, with Origin and Referer headers set to Microsoft’s website. A Google STUN server handles the NAT lookup that finds the host’s external address. Signaling runs through the Workers endpoint, and the operator’s reply is built to prevent a direct connection, which forces every byte through a Twilio TURN relay. The attacker’s real server address stays out of the packet capture. Cloudflare Workers exits the picture once the channel opens. Blocking *.workers.dev to cut off that signaling broadly affects legitimate Cloudflare Workers deployments at the same time. Commands come back as cmd.exe Traffic inside the channel carries two layers of encryption. DTLS covers the transport by specification, handled by the browser. msaRAT encrypts the payload separately, using a key negotiated the moment the C2 connection opens. Two of the frame types carry a command string, which the RAT hands to cmd.exe for execution. The output goes back out the same channel. The remaining frames open and close channels, perform the key exchange, and kill the browser process. Catch it at the host Szeliga was asked which vantage point gives the best odds of catching it. “The most reliable place to catch this is at the host, specifically where the browser is launched with set parameters. From a network perspective, the initial negotiation is conducted using HTTPS. From there, not only is the WebRTC traffic encrypted with DTLS and can blend in with ordinary traffic, the RAT adds its own encryption layer to the data. In this case, the earlier the activity can be detected and interrupted on the endpoint, the better,” he explained. A Chrome or Edge process started with a remote debugging port and a user-data directory the malware specifies is the observable event, and it follows an MSI landing in ProgramData. Talos published a ClamAV signature, Win.Downloader.ChaosRaas-10060321-0. The indicators cover the delivery server, the signaling domain, and a file hash, and they also sit in the Talos GitHub repository. The signaling requests carry a HeadlessChrome user agent, one artifact the network still gets to see. The endpoint holds the rest.
helpnetsecurity.comJul 23, 2026extracted
USN-8517-1: ClamAV vulnerabilities
Details It was discovered that ClamAV incorrectly handled certain PE files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) It was discovered that ClamAV incorrectly handled certain 7z archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20215) It was discovered that ClamAV incorrectly handled extraction limits for certain InstallShield archives. A remote attacker could possibly use this issue to cause ClamAV to use excessive resources, leading to a denial of service. (CVE-2026-20216) It was discovered that ClamAV incorrectly handled certain ALZ... It was discovered that ClamAV incorrectly handled certain PE files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) It was discovered that ClamAV incorrectly handled certain 7z archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20215) It was discovered that ClamAV incorrectly handled extraction limits for certain InstallShield archives. A remote attacker could possibly use this issue to cause ClamAV to use excessive resources, leading to a denial of service. (CVE-2026-20216) It was discovered that ClamAV incorrectly handled certain ALZ archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20243) It was discovered that ClamAV incorrectly handled certain DMG files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20244) The problem can be corrected by updating your system to the following package versions: Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
ubuntu.comJul 8, 2026extracted
New ClamAV security patch closes seven scanner bugs dating back two decades
New ClamAV security patch closes seven scanner bugs dating back two decades Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 and 1.4.5, carrying fixes for seven security flaws along with smaller hardening changes. Packer and PE parsing flaws Most of the patched bugs sit in the code that unpacks and parses executable formats, the part of a scanner built to handle hostile input. CVE-2026-20213 is an integer overflow in the PE rebuild size calculation that a malformed Aspack-packed file can trigger, leading to a heap buffer overflow write. The related CVE-2026-20214 covers an FSG unpacker loop underflow that can write past the section array during a scan of a crafted PE file. Both reach far back through the codebase, with the FSG issue present in builds dating to 2004. CVE-2026-20217 rounds out the PE group. A bug in the PESpin unpacker cleanup path could free pointers into the scanned file buffer and crash the scanner. That flaw has lived in the code since 2005. Archive and image format bugs Three more fixes address archive and disk-image handling. CVE-2026-20215 is a 7z parser substream count overflow that can under-allocate parser metadata arrays and then write past them when reading a crafted archive. CVE-2026-20243 covers ALZ parser size handling errors that can make malformed ALZ archives panic, abort the scanner, or skip expected scan-limit handling. CVE-2026-20216 is an InstallShield archive extraction limit bypass that can write far more temporary data than intended and drain temporary storage. The last parsing flaw, CVE-2026-20244, sits in the 32-bit DMG parser. A short mish stripe table could pass validation and crash the scanner. This one affects only 32-bit builds, going back to version 0.98.1, and leaves 64-bit builds untouched. Quarantine race condition The releases also harden the quarantine actions in clamscan, clamdscan, and clamonacc against time-of-check/time-of-use races. Under unsafe quarantine directory settings, those races could redirect files as the scanner copied, moved, or removed them. Hiroki Imai of Ricerca Security, Inc. reported the issue. Version 1.5.3 adds a few items beyond 1.4.5. It upgrades the Rust tar dependency to resolve two RUSTSEC advisories and moves the Rust openssl dependency past CVE-2026-41676. Metadata preclass scans now run before the final scan verdict. A ClamOnAcc fix addresses hash bucket list corruption when two watched paths land in the same bucket. Both releases raise the minimum CMake version to 3.17 to repair Linux builds that link static dependencies against libcurl v8.21.0. The release files are available on the GitHub release page, and through Docker Hub in Alpine and Debian containers. Must read: 25 open-source cybersecurity tools that don’t care about your budget GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comJul 5, 2026extracted
Proxmox releases Mail Gateway 9.1 with quarantine and backup encryption changes
Proxmox releases Mail Gateway 9.1 with quarantine and backup encryption changes Proxmox Mail Gateway 9.1 adds updated system components, changes to the spam quarantine interface, and encryption for backups. It works as a mail proxy positioned between the firewall and internal mail servers, screening incoming and outgoing traffic for spam, viruses, Trojans, and phishing attempts. Updated system components Version 9.1 runs on Debian 13.5 Trixie and ships with Linux kernel 7.0 as the stable default. The release includes SpamAssassin 4.0.2 with continuously updated rulesets, ClamAV 1.4.4, PostgreSQL 17, and ZFS 2.4. These versions track the current major open-source security packages that the platform depends on. Quarantine interface changes Several updates apply to the web-based quarantine, where administrators and end users review filtered messages. Within shared mailboxes, users can now mark quarantined emails as “seen,” which keeps teams from auditing the same message twice. The status appears inline as a checkmark and can be switched on or off with an action button. The quarantine overview shows the positive and negative parts of an email’s spam score at the same time, giving administrators direct insight into the reasons a message crossed a filtering threshold. External images in quarantined messages can be set to load only on demand. A user who wants to view those images clicks a “Load Images” button in the quarantine view. This lets staff inspect message content and keeps external image requests from firing automatically, which protects privacy and reduces exposure to web-based threats. Administrators gain a “Copy Link” option on the admin dashboard. The option copies a recipient’s private quarantine access link, which an administrator can then pass along through any channel or build into a custom interface. Encryption for backups Version 9.1 adds native encryption for backups sent to a Proxmox Backup Server instance. The encryption covers email configuration settings, user-created rule system data, and historic and private statistics data. Proxmox Mail Gateway encrypts this material on the client side before it leaves the system, and it stays encrypted on the backup storage target. Availability and pricing Proxmox Mail Gateway 9.1 is open-source software and is available for download now. A complete ISO image carries the entire feature set and installs on bare-metal hardware through an installation wizard. Administrators can also place the software on an existing Debian system or run it as a Linux Container on Proxmox VE. Existing deployments on version 8.2 or 9.0 can move to 9.1 through a tested upgrade path in the APT package management system.
helpnetsecurity.comJun 11, 2026extracted
Cisco Patches Critical Vulnerabilities in Enterprise Networking Products
Cisco on Wednesday announced fixes for 50 vulnerabilities across its products, including 48 affecting Firewall ASA, Secure FMC, and Secure FTD appliances. Cisco released a March 2026 bundled publication containing 25 security advisories that describe the security defects affecting its enterprise networking products, including two advisories detailing critical-severity flaws. The first of them, tracked as CVE-2026-20079 (CVSS score of 10/10), is described as an authentication bypass in the web interface of Cisco Secure FMC software. Successful exploitation of the bug allows attackers to execute arbitrary scripts on vulnerable deployments and gain root access to the underlying OS. “This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device,” Cisco explains. The web interface of Secure FMC is also impacted by CVE-2026-20131 (CVSS score of 10/10), a critical issue that could allow attackers to execute Java code with root privileges. The weakness exists because a user-supplied Java byte stream is insecurely deserialized, allowing attackers to send crafted serialized objects to trigger the exploitation. “A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root,” Cisco explains, noting that the exploitation risk is lower for FMC management interfaces that are not accessible from the internet. On Wednesday, Cisco also announced fixes for nine high-severity vulnerabilities in the ASA Firewall, Secure FMC, and Secure FTD appliances, which could be exploited to conduct SQL injection attacks, cause denial-of-service (DoS) conditions, and read, create, or overwrite sensitive files. The remaining three dozen flaws addressed in Cisco’s enterprise networking appliances are medium-severity issues. Cisco also announced patches for medium-severity security defects in Webex and ClamAV. Additional information can be found on Cisco’s security advisories page. Cisco says it is not aware of any of these vulnerabilities being exploited in the wild. Users are advised to update their deployments as soon as possible. Related: Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers Related: Cisco, F5 Patch High-Severity Vulnerabilities Related: Hackers Targeting Cisco Unified CM Zero-Day Related: Cisco Patches Vulnerability Exploited by Chinese Hackers
securityweek.comMar 5, 2026extracted
IPFire ships its 200th core update with a new domain blocklist and kernel upgrade
IPFire ships its 200th core update with a new domain blocklist and kernel upgrade Network firewall distribution IPFire released Core Update 200, marking the 200th incremental update to the 2.29 branch. The release bundles a kernel upgrade, a beta domain blocklist service, security patches for OpenSSL and glibc, and a range of component updates. The kernel has been rebased on Linux 6.18.7 LTS, bringing updated hardware security mitigations alongside network throughput and latency improvements. Linux developers deprecated ReiserFS support in this kernel line, and IPFire installations running on that filesystem cannot apply the update without first reinstalling on a supported filesystem. IPFire DBL enters beta The release introduces IPFire DBL, a domain blocklist the project is building to replace the retired Shalla list, which the web proxy previously relied on to filter malware, social networking, and adult content. DBL is available in two places: the URL filter for proxy-based blocking, and as a Suricata rules source. When used with Suricata, the blocklist enables deep packet inspection across DNS, TLS, HTTP, and QUIC connections. The project describes DBL as an early beta and is soliciting community feedback. A DNS Firewall with native content filtering is listed on the roadmap as the next major milestone. Suricata and IPS changes A cache management fix addresses a bug introduced in the previous update, where Suricata’s pre-compiled signature cache grew without limit and consumed disk space. A backported patch now causes Suricata to clean up unused signatures automatically. The Suricata reporter has been updated to surface hostname information and additional protocol metadata for alerts involving DNS, HTTP, TLS, and QUIC connections. That data will appear in alert emails and PDF reports, giving administrators more context when investigating policy violations. OpenVPN configuration updates Several OpenVPN client configuration behaviors have changed. MTU values will now be pushed from the server rather than baked into client configs, giving administrators flexibility to adjust the value after deployment. The OTP authentication token will also be pushed server-side when OTP is enabled. The CA certificate has been removed from client configuration files because it is already contained in the PKCS12 container; its presence was causing import failures in NetworkManager on the command line. DNS proxy goes multi-threaded Unbound, the DNS proxy component, will now launch one thread per CPU core. Previously it ran on a single thread. The change is expected to reduce response times under load. Wireless access point fixes Support for 802.11a/g has been restored after being dropped unintentionally in a prior release. A separate fix prevents hostapd from flooding logs with debug output when debugging is enabled. PSK values containing special characters are now accepted. Security patches OpenSSL has been updated to version 3.6.1, patching twelve CVEs: CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, and CVE-2026-22796. The glibc library received patches for CVE-2026-0861, CVE-2026-0915, and CVE-2025-15281. Package updates Notable component versions in this release include Apache 2.4.66, BIND 9.20.18, cURL 8.18.0, OpenVPN 2.6.17, strongSwan 6.0.4, Suricata 8.0.3, Unbound 1.24.2, ClamAV 1.5.1, Samba 4.23.4, and Tor 0.4.8.21. Must read: 40 open-source tools redefining how security teams secure the stack Firmware scanning time, cost, and where teams run EMBA Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comMar 2, 2026extracted