
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-37167 is a code injection vulnerability in ClamAV's ClamBC bytecode interpreter affecting versions prior to 0.103.0-rc. The flaw stems from weak input validation in function name encoding within the bytecode interpreter, allowing attackers to manipulate bytecode function names and potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine (CWE-94). It carries a CVSS v3.1 base score of 8.4 (High) with a local attack vector requiring no privileges or user interaction (Red Hat CVE, Feedly). The CVE was published to NVD on February 12, 2026.
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and resides in the ClamBC bytecode interpreter's function name processing logic. Insufficient validation of function name encoding allows an attacker to craft malicious bytecode signatures with manipulated function names that bypass expected constraints, potentially triggering arbitrary code execution within the ClamAV engine. Exploitation requires local access and the ability to supply untrusted bytecode to the ClamAV engine — for example, by enabling the BytecodeUnsigned option or placing crafted .cbc files in a scanned path. The Cisco-Talos patch commit added explicit documentation warnings against running bytecode signatures from untrusted sources across man pages, help strings, and configuration samples (ClamAV Commit).
Successful exploitation can result in arbitrary code execution within the ClamAV process, impacting confidentiality, integrity, and availability — all rated High in the CVSS scoring. An attacker could gain unauthorized access to sensitive data processed by ClamAV, modify system state, or disrupt the availability of the antivirus engine. Because ClamAV is often deployed as a system-level service, code execution in its context may facilitate privilege escalation or lateral movement depending on the deployment environment (Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.032% (0.000320), indicating a very low probability of exploitation in the near term. Exploitation requires local access and the ability to supply crafted bytecode to the ClamAV engine, which limits the practical attack surface.
BytecodeUnsigned enabled in clamd.conf or invoked with --bytecode-unsigned in clamscan, which allows loading bytecode from outside digitally signed database files..cbc file) with manipulated function names that exploit the weak input validation in the ClamBC bytecode interpreter's function name encoding logic.clambc tool for testing.clambc against the crafted signature..cbc bytecode files present in ClamAV signature directories or scanned paths; files with unusual function name patterns in bytecode content.BytecodeUnsigned yes enabled in clamd.conf or --bytecode-unsigned flag used in clamscan invocations, indicating unsigned bytecode loading is permitted.clamd) or scanner (clamscan) process; unexpected network connections or file writes originating from ClamAV processes.Upgrade ClamAV to version 0.103.0-rc or later, which addresses the vulnerability (Red Hat CVE). As an immediate workaround, ensure BytecodeUnsigned is set to no (the default) in clamd.conf and avoid using the --bytecode-unsigned flag with clamscan, which prevents loading bytecode from outside digitally signed .cld/.cvd files. Restrict access to ClamAV signature directories to prevent placement of untrusted bytecode files, and monitor ClamAV processes for anomalous behavior (ClamAV Commit).
Red Hat has published a CVE advisory page for this vulnerability, and the Cisco-Talos ClamAV team addressed the issue by adding explicit warnings in documentation, man pages, help strings, and configuration samples cautioning against running bytecode signatures from untrusted sources (ClamAV Commit, Red Hat CVE). No significant broader media coverage or notable researcher commentary has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."