CVE-2025-26790: Low severity WithSecure Web security/Antivirus engine (Capricorn engine) vulnerability
Withsecure Atlant with Capricorn engine before 2025-01-2002 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker would need to cause the Capricorn antivirus engine to process a crafted document file. The vector is network-accessible, requires no privileges or user interaction, but has high attack complexity.
What is the practical impact?
Successful exploitation can cause a remote denial of service through an out-of-bounds memory read. The supplied metrics indicate no confidentiality or integrity impact, with availability impact limited to low.
Which deployments are affected?
Deployments using the WithSecure Web Security/Antivirus Capricorn engine before 2025-01-20_02 are affected. The provided information does not state whether the vulnerable engine is enabled in default configurations.
How can I determine whether remediation is needed?
Check the installed Capricorn engine version or update level. Systems running a version before 2025-01-20_02 require remediation; the provided data does not identify a workaround when updating is not immediately possible.