CVE-2025-20128

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*
cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*

History

06 Aug 2025, 14:11

Type Values Removed Values Added
CPE cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*
cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Cisco secure Endpoint Private Cloud
Cisco secure Endpoint
Clamav
Cisco
Clamav clamav
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA - Third Party Advisory
References () https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html - () https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html - Vendor Advisory

18 Feb 2025, 20:15

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : unknown

22 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-22 17:15

Updated : 2025-08-06 14:11


NVD link : CVE-2025-20128

Mitre link : CVE-2025-20128


JSON object : View

Products Affected

cisco

  • secure_endpoint_private_cloud
  • secure_endpoint

clamav

  • clamav
CWE
CWE-122

Heap-based Buffer Overflow