CVE-2025-20128
published 2025-01-22CVE-2025-20128: A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.51%
71.6th percentile
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.
For a description of this vulnerability, see the .
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_cisco5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerability
vendor_ubuntu·2025-01-27
CVE-2025-20128 ClamAV vulnerability
Title: ClamAV vulnerability
Summary: ClamAV could be made to crash if it opened a specially crafted file.
It was discovered that ClamAV incorrectly handled decrypting OLE2 content.
A remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Cisco
ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
vendor_cisco·2025-01-22·CVSS 5.3
CVE-2025-20128 [MEDIUM] CWE-122 ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.
For a description of this vulnerability, see the ClamAV blog.
Cisco has released software updates that address this vulnerab
Debian
CVE-2025-20128: clamav - A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine ...
vendor_debian·2025·CVSS 5.3
CVE-2025-20128 [MEDIUM] CVE-2025-20128: clamav - A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine ...
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Scope: local
bo
Cisco
ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20128 ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
CVE-2025-20128: ClamAV OLE2 File Format Decryption Denial of Service Vulnerability
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the ClamAV blog . Cisco has released software updates that addres
OSV
CVE-2025-20128: A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a d
osv·2025-01-22·CVSS 7.5
CVE-2025-20128 [HIGH] CVE-2025-20128: A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a d
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
GHSA
GHSA-6j5q-p9xp-3cc6: A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a d
ghsa_unreviewed·2025-01-22
CVE-2025-20128 [MEDIUM] CWE-120 GHSA-6j5q-p9xp-3cc6: A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a d
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.
For a description of this vulnerability, see the .
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Suricata
ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20128)
suricata·2025-02-27·CVSS 7.2
CVE-2023-20128 [HIGH] ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20128)
ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20128)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20128)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/cgi-bin/import_config.cgi"; fast_pattern; http.content_type; content:"multipart/form-data|3b|"; http.request_body; content:"name|3d 22|USBconfigfile|22|"; content:"|3b|"; distance:0; reference:url,www.iotsec-zone.com/article/383; reference:cve,2023-20128; classtype:web-application-attack; sid:2060434; rev:1; metadata:affected_product Cisco_RV_Series, attack_target Server, tls_state TLSDecrypt, created_at 2025_02_27, cve CVE_2023_20128, deployment Perimeter, deployment I
No public exploits indexed.
Bleepingcomputer
Cisco warns of denial of service flaw with PoC exploit code
blogs_bleepingcomputer·2025-01-22·CVSS 5.3
CVE-2025-20128 [MEDIUM] Cisco warns of denial of service flaw with PoC exploit code
## Cisco warns of denial of service flaw with PoC exploit code
## Sergiu Gatlan
Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code.
Tracked as CVE-2025-20128, the vulnerability is caused by a heap-based buffer overflow weakness in the Object Linking and Embedding 2 (OLE2) decryption routine, allowing unauthenticated, remote attackers to trigger a DoS condition on vulnerable devices.
If this vulnerability is successfully exploited, it could cause the ClamAV antivirus scanning process to crash, preventing or delaying further scanning operations.
"An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device," Cisco expl
Wiz
CVE-2026-20031 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-20031 [HIGH] CVE-2026-20031 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20031 :
Clam AntiVirus vulnerability analysis and mitigation
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.
Source : NVD
## 5.3
Score
Published March 4, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Clam AntiVirus
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Proba
Wiz
CVE-2020-37167 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2020-37167 [HIGH] CVE-2020-37167 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2020-37167 :
Clam AntiVirus vulnerability analysis and mitigation
ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.
Source : NVD
## 8.6
Score
Published February 12, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Clam AntiVirus
Linux Ubuntu
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
clamav
2025-01-22
Published