Cisco warns of high-severity ClamAV flaws with public exploits
Summary
Cisco has issued a warning about two critical vulnerabilities in the ClamAV scanning process, part of Cisco Secure Endpoint Connector. These flaws allow attackers to trigger denial-of-service (DoS) attacks, causing the antivirus scanner to crash.
IFF Assessment
The disclosure of critical vulnerabilities with public exploits poses a direct threat to defenders by enabling denial-of-service attacks.
Severity
The vulnerabilities allow for denial-of-service (DoS) attacks, which typically have a medium to high impact. The ability for public exploits to exist suggests a lower attack complexity and thus a higher exploitability.
Defender Context
Defenders should prioritize patching or mitigating these ClamAV vulnerabilities to prevent service disruption. The existence of public exploits means that exploitation could be widespread and relatively easy to execute by threat actors.