← Vulnerability feed

Vulnerability record · CVE-2024-20328 · published 1 March 2024

CVE-2024-20328: ClamAV VirusEvent feature command injection via crafted file names

Clamav · Clamav

ClamAV's VirusEvent feature mishandles file names, allowing a local attacker to inject command-line sequences that the application executes with the privileges of the ClamAV service account. The flaw is an OS command injection (CWE-78) and only affects systems where VirusEvent configuration options are in use. ClamAV has released updates that fix it, and no workarounds exist.

5.3 CVSS 3.1 Medium EPSS 85% · top 0.3% CWE-78 · OS command injection
5.3CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerability is due to unsafe handling of file names. A local attacker could exploit this vulnerability by supplying a file name containing command-line sequences. When processed on a system using configuration options for the VirusEvent feature, the attacker could cause the application to execute arbitrary commands. ClamAV has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows local arbitrary command execution as the ClamAV service account and carries a very high EPSS score, though it requires local access and a specific VirusEvent configuration.

What it is

ClamAV's VirusEvent feature mishandles file names, allowing a local attacker to inject command-line sequences that the application executes with the privileges of the ClamAV service account. The flaw is an OS command injection (CWE-78) and only affects systems where VirusEvent configuration options are in use. ClamAV has released updates that fix it, and no workarounds exist.

Impact

An attacker who can place a maliciously named file where ClamAV scans it can execute arbitrary commands as the ClamAV service account, gaining that account's level of read, write, and execution access on the host.

Attack surface

Reached locally: the attacker must be able to supply a file whose name contains command-line sequences and have it processed by a ClamAV instance configured with VirusEvent options. The CVSS vector (AV:L/PR:L/UI:N) indicates local access with low privileges and no user interaction.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.848 probability, 99.7th percentile), suggesting elevated near-term exploitation likelihood.

What to do

  • Upgrade ClamAV to the fixed release referenced in the vendor advisory (1.3.0, 1.2.2, or 1.0.5) as the primary remediation.
  • If VirusEvent is not required, remove or disable VirusEvent configuration options to eliminate the vulnerable code path.
  • Run ClamAV under a dedicated, least-privilege service account with no unnecessary filesystem or network permissions.
  • Restrict which users and processes can write files into directories that ClamAV scans, and sanitize or quarantine untrusted file names before scanning.
  • Monitor vendor and distribution advisories for updated packages, since no workaround exists.

Detection

  • Audit ClamAV configuration files for active VirusEvent directives and flag any host still using them.
  • Monitor process trees for ClamAV spawning unexpected child processes or shells, which would indicate command injection.
  • Alert on file names containing shell metacharacters (semicolons, backticks, $(), pipes) appearing in scanned directories.
  • Review ClamAV service account activity for anomalous command execution or file writes outside its normal scan behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20328 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0098Clamav vulnerabilityClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafte…EPSS 4.9%10.0CVE-2009-1372Clamav memory buffer overflow vulnerabilityStack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial…EPSS 7.6%10.0CVE-2008-3914Clamav information exposure vulnerabilityMultiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path…EPSS 3.6%10.0CVE-2008-0728Clamav vulnerabilityThe unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."EPSS 2.8%10.0CVE-2006-1615Clamav vulnerabilityMultiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary…EPSS 12%9.8CVE-2025-20260Clamav heap-based buffer overflow vulnerabilityA vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a…EPSS 1.6%9.8CVE-2023-20032Cisco secure endpoint classic buffer overflow vulnerabilityOn Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamA…EPSS 29%9.8CVE-2013-7087Clamav memory buffer overflow vulnerabilityClamAV before 0.97.7 has WWPack corrupt heap memoryEPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2024-20328), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.