ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability
TL;DR π
- A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV onβ¦
- No fixed release listed yet; apply mitigations and monitor.
- Workarounds are documented in the advisory.
- CVEs: CVE-2025-20234.
What happened π΅οΈββοΈ
Impacts of ClamAV DoS Vulnerability on Affected Platforms
This vulnerability, which has a Medium Security Impact Rating (SIR), affects Linux, Mac, and Windows-based platforms. Exploitation of the vulnerability could cause the scanning process to crash, delaying or preventing further scanning operations. However, overall system stability is not affected. See the Assessing Security Risk [“https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#asr”] section of the Cisco Security Vulnerability Policy for information about vulnerability scoring and SIRs.
Cisco Secure Endpoint Connector, which is distributed from Cisco Secure Endpoint Private Cloud, is affected by this vulnerability. Cisco Secure Endpoint Private Cloud is not affected.
Affected products π₯οΈ
The following table lists Cisco products that are affected by the vulnerability that is described in this advisory. Customers should refer to the associated Cisco bug IDs for further details. Affected Cisco Software Platform CVSS Base Score Security Impact Rating Cisco Bug ID First Fixed Release Secure Endpoint Connector for Linux CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Medium CSCwo45640 [“https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo45640”] 1.26.1 Secure Endpoint Connector for Mac CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Medium CSCwo45640 [“https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo45640”] 1.26.1 Secure Endpoint Connector for Windows CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Medium CSCwo45640 [“https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo45640”] 7.5.21 8.4.5 Secure Endpoint Private Cloud CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Medium CSCwo45640 [“https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo45640”] 4.2.2 or earlier with updated connectors Cisco products may be impacted differently depending on implementation and usage of ClamAV. For information on the effects of this vulnerability on specific Cisco products, see the Details ["#details"] section of this advisory.
Fixed software π§
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability 8.4.51 | Secure Endpoint Private Cloud |
Workarounds π§―
There are no workarounds that address this vulnerability.
Risk in context π―
Use vendor CVSS for prioritization. Consider exposure and asset criticality.
Fast facts β‘
- Advisory: cisco-sa-clamav-udf-hmwd9nDy
- Initial release: 2025-06-18T16:00:00 UTC
- Last updated: 2025-06-18T16:00:00 UTC
For leadership π§
Executive summary. A crafted file scanned by ClamAV on Cisco Secure Endpoint Connector can crash the antivirus scanning process, temporarily halting malware detection on affected endpoints without needing credentials or user interaction. Fixed releases exist for the Linux, Mac and Windows connectors, so this should be scheduled into the next maintenance window rather than treated as an emergency.
Why it matters:
- The flaw sits in ClamAV’s UDF file parsing, so any file with UDF content submitted for scanning can trigger the crash - no authentication or user action required.
- Secure Endpoint Connector for Linux, Mac and Windows are all affected, meaning most endpoint deployments running Cisco’s connector are in scope.
- A crashed scanning process delays or blocks further malware scanning on that endpoint, though the underlying host and Secure Endpoint Private Cloud itself remain stable.
- There are no workarounds, so the only remediation path is upgrading the connector to the fixed release for your platform.
Now / Next / Later:
- Now: Identify which Secure Endpoint Connector versions (Linux, Mac, Windows) are deployed across your estate using the Cisco bug ID CSCwo45640 reference, since no workaround exists.
- Next: Upgrade Secure Endpoint Connector to the first fixed release for each platform (1.26.1 for Linux/Mac, 7.5.21 or 8.4.5 for Windows) and update Secure Endpoint Private Cloud to 4.2.2 or earlier with updated connectors as applicable.
- Later: Add ClamAV/Secure Endpoint Connector versions to routine patch tracking so future UDF parsing or file-scanning fixes are applied promptly rather than discovered ad hoc.