Cisco Flags High-Severity Flaws in ClamAV Antivirus Software—Exploit Code Already Public
Cisco has issued a security advisory about high-severity vulnerabilities found in ClamAV, the widely used open-source antivirus engine. According to Cisco, remote and unauthenticated attackers—meaning they don't need a username or password—could exploit these flaws to trigger a denial-of-service (DoS) condition, potentially crashing the software or making it unresponsive.
What makes this warning particularly urgent is that proof-of-concept (PoC) exploit code is already publicly available. This significantly lowers the bar for attackers, as they don't need advanced technical skills to attempt an exploit—increasing the likelihood of opportunistic attacks against unpatched systems.
ClamAV is commonly used by businesses of all sizes, including many small and medium enterprises, as part of email security gateways, file scanning tools, and endpoint protection systems. A successful attack could disrupt antivirus scanning capabilities, leaving systems temporarily unprotected or causing service outages. Businesses relying on ClamAV, whether directly or through integrated security products, should check with their vendors and apply any available patches as soon as possible.