CVE-2020-37167
Clam AntiVirus vulnerability analysis and mitigation

Overview

CVE-2020-37167 is a code injection vulnerability in ClamAV's ClamBC bytecode interpreter affecting versions prior to 0.103.0-rc. The flaw stems from weak input validation in function name encoding within the bytecode interpreter, allowing attackers to manipulate bytecode function names and potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine (CWE-94). It carries a CVSS v3.1 base score of 8.4 (High) with a local attack vector requiring no privileges or user interaction (Red Hat CVE, Feedly). The CVE was published to NVD on February 12, 2026.

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and resides in the ClamBC bytecode interpreter's function name processing logic. Insufficient validation of function name encoding allows an attacker to craft malicious bytecode signatures with manipulated function names that bypass expected constraints, potentially triggering arbitrary code execution within the ClamAV engine. Exploitation requires local access and the ability to supply untrusted bytecode to the ClamAV engine — for example, by enabling the BytecodeUnsigned option or placing crafted .cbc files in a scanned path. The Cisco-Talos patch commit added explicit documentation warnings against running bytecode signatures from untrusted sources across man pages, help strings, and configuration samples (ClamAV Commit).

Impact

Successful exploitation can result in arbitrary code execution within the ClamAV process, impacting confidentiality, integrity, and availability — all rated High in the CVSS scoring. An attacker could gain unauthorized access to sensitive data processed by ClamAV, modify system state, or disrupt the availability of the antivirus engine. Because ClamAV is often deployed as a system-level service, code execution in its context may facilitate privilege escalation or lateral movement depending on the deployment environment (Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.032% (0.000320), indicating a very low probability of exploitation in the near term. Exploitation requires local access and the ability to supply crafted bytecode to the ClamAV engine, which limits the practical attack surface.

Exploitation steps

  1. Reconnaissance: Identify systems running ClamAV versions prior to 0.103.0-rc, particularly those with BytecodeUnsigned enabled in clamd.conf or invoked with --bytecode-unsigned in clamscan, which allows loading bytecode from outside digitally signed database files.
  2. Craft malicious bytecode: Create a malicious ClamAV bytecode signature (.cbc file) with manipulated function names that exploit the weak input validation in the ClamBC bytecode interpreter's function name encoding logic.
  3. Deliver the payload: Place the crafted bytecode file in a directory that ClamAV will scan or load as a signature database, or supply it directly to the clambc tool for testing.
  4. Trigger execution: Cause ClamAV to load and execute the malicious bytecode — either by initiating a scan of the directory containing the file or by directly invoking clambc against the crafted signature.
  5. Achieve code execution: The manipulated bytecode executes arbitrary code within the ClamAV engine process, potentially enabling data access, system modification, or further exploitation (ClamAV Commit).

Indicators of compromise

  • File System: Unexpected or unsigned .cbc bytecode files present in ClamAV signature directories or scanned paths; files with unusual function name patterns in bytecode content.
  • Configuration: BytecodeUnsigned yes enabled in clamd.conf or --bytecode-unsigned flag used in clamscan invocations, indicating unsigned bytecode loading is permitted.
  • Process: Unusual child processes spawned by the ClamAV daemon (clamd) or scanner (clamscan) process; unexpected network connections or file writes originating from ClamAV processes.
  • Logs: ClamAV log entries referencing loading of unsigned bytecode signatures from non-standard paths; errors or crashes in the ClamBC bytecode interpreter.

Mitigation and workarounds

Upgrade ClamAV to version 0.103.0-rc or later, which addresses the vulnerability (Red Hat CVE). As an immediate workaround, ensure BytecodeUnsigned is set to no (the default) in clamd.conf and avoid using the --bytecode-unsigned flag with clamscan, which prevents loading bytecode from outside digitally signed .cld/.cvd files. Restrict access to ClamAV signature directories to prevent placement of untrusted bytecode files, and monitor ClamAV processes for anomalous behavior (ClamAV Commit).

Community reactions

Red Hat has published a CVE advisory page for this vulnerability, and the Cisco-Talos ClamAV team addressed the issue by adding explicit warnings in documentation, man pages, help strings, and configuration samples cautioning against running bytecode signatures from untrusted sources (ClamAV Commit, Red Hat CVE). No significant broader media coverage or notable researcher commentary has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Clam AntiVirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20348HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.5
NoYesAug 07, 2026
CVE-2026-20347HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4
NoYesAug 07, 2026
CVE-2026-20346HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4
NoYesAug 07, 2026
CVE-2026-20345HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-70622HIGH7.1
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.5
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management