CVE-2024-20290 describes a denial-of-service vulnerability in the OLE2 file format parser of ClamAV, impacting various Cisco and Fedora products. An unauthenticated, remote attacker can trigger a heap buffer over-read by submitting a specially crafted OLE2 file for scanning. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited over the network with low complexity, requiring no user interaction, to cause a complete denial of service. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion and media coverage, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.17CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:* | ||
>= 8.0.1.21160, < 8.2.3.30119CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:* | ||
< 3.8.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.