QID 379357
Date Published: 2024-02-08
QID 379357: Cisco Secure Endpoint (Formerly AMP) Denial of Service (DoS) Vulnerability (cisco-sa-clamav-hDffu6t)
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Affected Versions:
Secure Endpoint Connector for Windows Prior to 7.5.17
Secure Endpoint Connector for Windows Prior to 8.2.1
QID Detection Logic:
QID checks for the vulnerable version of Secure Endpoint Connector through Registry Key
A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources.
Solution
Vendor has released fix to address these vulnerabilities. Refer to cisco-sa-clamav-hDffu6t
Vendor References
- cisco-sa-clamav-hDffu6t -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-hDffu6t
CVEs related to QID 379357
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-clamav-hDffu6t |
|