Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code. Tracked as CVE-2025-20128, the vulnerability is caused by a heap-based buffer overflow weakness in the Object Linking and Embedding 2 (OLE2) decryption routine, allowing unauthenticated, remote attackers to trigger a DoS condition on vulnerable devices. If this vulnerability is successfully exploited, it could cause the ClamAV antivirus scanning process to crash, preventing or delaying further scanning operations. "An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device," Cisco explained. "A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software." However, in an advisory issued today, the company noted that overall system stability would not be affected even after successful attacks. The vulnerable products list includes the Secure Endpoint Connector software for Linux, Mac, and Windows-based platforms. This solution helps ingest Cisco Secure Endpoint audit logs and events into security information and event management (SIEM) systems like Microsoft Sentinel. While the Cisco Product Security Incident Response Team (PSIRT) said it has no evidence of in-the-wild exploitation, it added that CVE-2025-20128 exploit code is already available. "The Cisco PSIRT is aware that p...
Cisco warns of denial of service flaw with PoC exploit code
BleepingComputer
·Sergiu Gatlan
·Published Jan 22, 2025
·Updated
Affected Software
8 affected components
Cisco ClamAV
Cisco Secure Endpoint Connector
Cisco Cisco BroadWorks
Cisco Cisco Meeting Management
Cisco ASA
Cisco Firepower Threat Defense (FTD)
Cisco Ultra-Reliable Wireless Backhaul (URWB)
Cisco ClamAV
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a denial-of-service vulnerability in Cisco's ClamAV software, which has been assigned the identifier CVE-2025-20128.
2
What security implications are discussed?
The article highlights that the vulnerability could be exploited to cause a denial-of-service condition, impacting the availability of affected systems.
3
What products or software are affected?
The affected products include Cisco ClamAV, Cisco Secure Endpoint Connector, Cisco BroadWorks, Cisco Meeting Management, Cisco ASA, and Cisco Firepower Threat Defense.
4
Is there a patch available for the vulnerability?
Yes, Cisco has released security updates to patch the ClamAV denial-of-service vulnerability.
5
What type of vulnerability is CVE-2025-20128?
CVE-2025-20128 is categorized as a heap-based buffer overflow vulnerability.