CVE-2024-20290 - CVE House
Back to Database
Status published High CVE-2024-20290

A vulnerability in the OLE2 file format parser of ClamAV...

Vulnerability Description

A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20290

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Secure Endpoint, Cisco Secure Endpoint Private Cloud Administration Portal, Cisco Secure Endpoint Private Cloud Console
Vulnerable Versions:
6.0.9, 6.0.7, 6.1.5, 6.1.7, 6.1.9, 6.2.1, 6.2.5, 6.2.19, 6.2.3, 6.2.9, 6.3.5, 6.3.1, 6.3.7, 6.3.3, 7.0.5, 7.1.1, 7.1.5, 7.2.13, 7.2.7, 7.2.3, 7.2.11, 7.2.5, 7.3.1, 7.3.9, 7.3.3, 7.3.5, 8.1.7, 8.1.5, 8.1.3.21242, 8.1.7.21512, 8.1.3, 8.1.5.21322, 8.1.7.21417

Timeline

Official Publish: February 7th, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)