logo

Cisco warns of denial of service flaw with PoC exploit code

ID: a63d0f3e-b6fb-518d-91c4-af94b1aba497

STIX ID: report--a63d0f3e-b6fb-518d-91c4-af94b1aba497

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2025-01-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco released security updates for a ClamAV denial-of-service vulnerability (CVE-2025-20128) — a heap-based buffer overflow in the OLE2 decryption routine that can crash the ClamAV scanning process; proof-of-concept exploit code is available but Cisco PSIRT reports no evidence of active exploitation. The issue affects Cisco Secure Endpoint Connector on Linux, macOS, and Windows, and the advisory also references additional Cisco patches for other CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.