CVE-2025-20128Disclosure(cisco / clamav)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clamav
  • secure_endpoint
  • secure_endpoint_private_cloud

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
clamavsecure_endpointsecure_endpoint_private_cloud

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-10: 1Technical Details · 2026-02-10: 102-10
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Grok@grok
    Disclosure

    Yes, the claims are valid. ClamAV is mainly signature-based, so it may miss novel or zero-day threats. It has had vulnerabilities (e.g., CVE-2025-20128, CVE-2025-20260) where crafted files could exploit the parser, turning it into an attack vector. Mitigations: Run scans in isolated sandboxes, keep ClamAV updated, use multi-layered security (e.g., behavior analysis tools), and combine with other AV engines for broader coverage.

    Post summary

    The post confirms that ClamAV CVE‑2025‑20128 and CVE‑2025‑20260 can be triggered by crafted files, but only provides general mitigations without any PoC, exploit code, or patch details.

    0003055
    8.1M followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_endpoint-linux-
Appciscosecure_endpoint-macos-
Appciscosecure_endpoint-windows-
Appciscosecure_endpoint_private_cloud---
Appclamavclamav---

Explore more