CVE-2026-20345

Cisco · Secure Endpoint

A stack-based buffer overflow in the ClamAV GPT file parser within Cisco Secure Endpoint allows an unauthenticated, remote attacker to trigger memory corruption and denial of service.

Executive summary

A high-severity stack-based buffer overflow in the ClamAV parser of Cisco Secure Endpoint enables unauthenticated, remote attackers to trigger memory corruption, leading to service disruption.

Vulnerability

This vulnerability involves a stack-based buffer overflow (CWE-121) in the GPT file format parser. By delivering a specially crafted file, an unauthenticated, remote attacker can cause memory corruption, leading to a denial of service or other expanded impacts on the affected device.

Business impact

A stack-based buffer overflow is a critical flaw that can lead to system crashes or arbitrary code execution. Given the CVSS score of 7.5, this represents a major risk to business continuity and data security, as the exploitation of this component could render the endpoint defenseless against further malicious activity.

Remediation

Immediate Action: Visit the Cisco security advisory link provided in the enrichment data to identify the specific update path and apply the necessary patches.

Proactive Monitoring: Monitor for unexpected process crashes related to the Cisco Secure Endpoint agent and investigate any suspicious file activity.

Compensating Controls: Deploy WAF or network-based file scanning solutions to detect and quarantine malformed GPT files before they are parsed by the endpoint agent.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations must treat this vulnerability with high priority. Update all affected instances of Cisco Secure Endpoint to the latest patched version to ensure that memory corruption vulnerabilities in the ClamAV engine are effectively neutralized.