← Back

CVE-2020-26893

nvd nist
Published: Oct 16, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (running with an injected malicious dylib) to communicate with ClamXAV 3's helper tool and perform privileged operations. This occurs because of inadequate client verification in the helper tool.

Affected (1)

Products: Clamxav: Clamxav
1 product
Clamxav
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0 to 3.1.1

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.