Cisco patches ClamAV vulnerabilities causing denial of service and unauthorized file reads
Cisco has issued critical updates to address multiple ClamAV vulnerabilities that can trigger denial of service (DoS) on Windows endpoints and a file read vulnerability in Catalyst Center. Defenders running Secure Endpoint Connector should prioritize updating to mitigate risks of scanning engine termination. Patch immediately to prevent unauthorized file access or disruption of security services.
Summary
Cisco has released software updates to address several high-severity vulnerabilities affecting ClamAV within its Secure Endpoint Connector and a remote file read vulnerability in Cisco Catalyst Center. The ClamAV flaws could allow an unauthenticated attacker to disrupt scanning operations by submitting crafted files, while the Catalyst Center flaw enables unauthorized access to restricted container files via crafted HTTP requests.
Technical details: ClamAV vulnerabilities
The ClamAV vulnerabilities impact the Secure Endpoint Connector across Windows, Linux, and macOS platforms. These flaws can lead to a denial of service (DoS) condition by terminating the scanning engine process.
On Windows-based platforms, these vulnerabilities carry a High Security Impact Rating because the scanning process runs in a privileged security context. A successful exploit could cause the endpoint to become unresponsive, potentially requiring a manual system reboot to recover. While memory protections on modern 64-bit architectures may hinder remote code execution, legacy 32-bit Windows systems face higher risks.
The specific vulnerabilities include:
- CVE-2026-20216: A flaw in the InstallShield file format parser caused by improper handling of temporary resources during scanning.
- CVE-2026-20213: A memory corruption vulnerability in the PE (Portable Executable) file format parser due to insufficient boundary checks, which may result in an out-of-bounds buffer write.
- CVE-2026-20214: A memory corruption vulnerability in the FSG file format parser also caused by improper boundary checks during scanning.
On Linux and macOS platforms, these vulnerabilities carry a Medium Security Impact Rating. Exploitation may terminate the scanning engine and prevent further operations, though overall system stability is not affected.
Technical details: Cisco Catalyst Center
A separate vulnerability in Cisco Catalyst Center allows an unauthenticated, remote attacker to read arbitrary files from a restricted container. This issue stems from insufficient validation of user-supplied input. An attacker can exploit this by sending a crafted HTTP request to an affected device.
This flaw affects both virtual and hardware appliances, regardless of the specific device configuration.
Affected products and fixed versions
| Product | Platform | Fixed Release |
|---|---|---|
| Secure Endpoint Connector for Windows | Windows | 8.6.2 |
| Secure Endpoint Connector for Linux | Linux | 1.29.0 |
| Secure Endpoint Connector for Mac | macOS | 1.27.2 |
| Catalyst Center Hardware Appliances | Various | 3.1.6 GSMU200 |
| Catalyst Center Virtual (AWS/Azure) | AWS/Azure | 3.1.6 GSMU200 |
| Catalyst Center Virtual (VMware ESXi) | VMware | 2.3.7.11-VA |
Cisco confirmed that Secure Email Gateway and Secure Web Gateway are not affected by the ClamAV vulnerabilities.
Defender guidance
To mitigate these risks, implement the following actions:
- Update Cisco Secure Endpoint Connector: Upgrade to version 8.6.2 for Windows, 1.29.0 for Linux, or 1.27.2 for macOS to prevent scanning engine termination.
- Upgrade Catalyst Center: Transition all hardware and virtual appliances to the 3.1.6 GSMU200 release (or the equivalent fixed version for VMware ESXi users) to block unauthorized file access via crafted HTTP requests.
- Monitor Scanning Disruptions: Watch for unexpected terminations of ClamAV scanning processes, which may indicate an attempted DoS attack through malicious file submissions.
Sources
- https://www.securityweek.com/in-other-news-canadian-hacker-jailed-open-source-zero-days-two-sentenced-for-atm-jackpotting/
- https://github.com/bikini/exploitarium
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X
