rootpwn

Vulnerabilities

ClamAV Vulnerabilities Enable Remote DoS on Cisco Secure Endpoint Connectors

A bundle of seven CVEs (CVE‑2026‑20337 through CVE‑2026‑20348) in ClamAV lets attackers trigger a denial‑of‑service on Cisco Secure Endpoint Connector software. The flaw is most critical on Windows, where the scanner runs with elevated privileges, but still poses a medium risk on Linux and macOS. Cisco has pushed patches for all affected platforms; no work‑arounds exist. The Private Cloud service itself remains unaffected, though its on‑device connector is vulnerable.

Seven newly disclosed ClamAV bugs give a remote attacker the ability to crash the scanner and halt all file‑checking operations on Cisco’s Secure Endpoint Connector. The attacks rely on malformed input that overflows buffers within the ClamAV engine, leading to a DoS condition.

Impact by Platform

  • Windows – The scanner runs with system‑level rights, so a successful exploit can bring down the entire endpoint agent. Cisco rates the security impact as High for Windows.
  • Linux & macOS – The connector operates under a lower‑privileged user, reducing the damage scope. The impact is rated as Medium on these operating systems.
  • Secure Endpoint Private Cloud – The cloud‑hosted service is not affected, but the on‑device connector distributed from it is.

Mitigation

  • Apply the latest Cisco software updates that patch the ClamAV vulnerabilities.
  • No work‑arounds are available; the only defense is to install the fix promptly.
“Cisco has released updates that address these vulnerabilities in affected platforms. There are no workarounds that mitigate the issue.”

Security teams should verify that the updated connector is deployed across all endpoints and monitor for any abnormal scanning behavior.

ClamAV DoS Cisco Endpoint Windows Linux macOS

← All news