ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
Published Jan 22, 2025
7.5
HIGHCVSS 3.1
EPSS 1.57%
Description
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected products
-
Affected
- 1.10.0
- 1.10.1
- 1.10.2
- 1.11.0
- 1.11.1
- 1.12.0
- 1.12.1
- 1.12.2
- 1.12.3
- 1.12.4
- 1.12.5
- 1.12.6
- 1.12.7
- 1.13.0
- 1.13.1
- 1.13.2
- 1.14.0
- 1.6.0
- 1.7.0
- 1.8.0
- 1.8.1
- 1.8.4
- 1.9.0
- 1.9.1
- 6.1.5
- 6.1.7
- 6.1.9
- 6.2.1
- 6.2.19
- 6.2.3
- 6.2.5
- 6.2.9
- 6.3.1
- 6.3.3
- 6.3.5
- 6.3.7
- 7.0.5
- 7.1.1
- 7.1.5
- 7.2.11
- 7.2.13
- 7.2.3
- 7.2.5
- 7.2.7
- 7.3.1
- 7.3.3
- 7.3.5
- 7.3.9
- 8.1.3
- 8.1.3.21242
- 8.1.5
- 8.1.5.21322
- 8.1.7
- 8.1.7.21417
- 8.1.7.21512
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cisco | Cisco Secure Endpoint | unknown | Affected
|
Configuration 1
Configuration 2
- < 1.24.4
- < 1.25.1
- < 7.5.20
- ≥ 8.0.1.21160 · < 8.4.3
- < 4.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-2155 Advisory
- https://lists.debian.org/debian-lts-announce/2025/09/msg00006.html
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA Third Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data