QID 378545

Date Published: 2023-06-12

QID 378545: Cisco Advanced Malware Protection (AMP) Buffer Overflow Vulnerability (cisco-sa-clamav-q8DThCy)

A vulnerability in the HFS+ partition file parser of ClamAV could allow an unauthenticated, remote attacker to execute arbitrary code.

Affected Versions:
Cisco AMP for Endpoints Prior to Version 7.5.9

Cisco AMP for Endpoints 8.0 Prior to Version 8.1.5

QID Detection Logic:
QID checks for the vulnerable version of Cisco AMP through Registry Key

Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to cisco-sa-clamav-q8DThCy

    CVEs related to QID 378545

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-clamav-q8DThCy URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy