CVE-2024-20506

ClamAV Privilege Handling Escalation Vulnerability

Severity
Medium 6.1
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.1th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 4, 2024
Assigned by cisco

Description

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files. The vulnerability is due to allowing the ClamD process to write to its log file while privileged without checking if the logfile has been replaced with a symbolic link. An attacker could exploit this vulnerability if they replace the ClamD log file with a symlink to a critical system file and then find a way to restart the ClamD process. An exploit could allow the attacker to corrupt a critical system file by appending ClamD log messages after restart.

Affected products

Vendor Product Category Matched by
Cisco ClamAV Endpoint / EDR cna-assigner
Vendor-reported affected versions (1)
  • Cisco · ClamAV