Vulnerability record · CVE-2024-20328 · published 1 March 2024
CVE-2024-20328: ClamAV VirusEvent feature command injection via crafted file names
Clamav · Clamav
ClamAV's VirusEvent feature mishandles file names, allowing a local attacker to inject command-line sequences that the application executes with the privileges of the ClamAV service account. The flaw is an OS command injection (CWE-78) and only affects systems where VirusEvent configuration options are in use. ClamAV has released updates that fix it, and no workarounds exist.
Description
A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerability is due to unsafe handling of file names. A local attacker could exploit this vulnerability by supplying a file name containing command-line sequences. When processed on a system using configuration options for the VirusEvent feature, the attacker could cause the application to execute arbitrary commands. ClamAV has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Automated analysis
high priorityThe flaw allows local arbitrary command execution as the ClamAV service account and carries a very high EPSS score, though it requires local access and a specific VirusEvent configuration.
What it is
ClamAV's VirusEvent feature mishandles file names, allowing a local attacker to inject command-line sequences that the application executes with the privileges of the ClamAV service account. The flaw is an OS command injection (CWE-78) and only affects systems where VirusEvent configuration options are in use. ClamAV has released updates that fix it, and no workarounds exist.
Impact
An attacker who can place a maliciously named file where ClamAV scans it can execute arbitrary commands as the ClamAV service account, gaining that account's level of read, write, and execution access on the host.
Attack surface
Reached locally: the attacker must be able to supply a file whose name contains command-line sequences and have it processed by a ClamAV instance configured with VirusEvent options. The CVSS vector (AV:L/PR:L/UI:N) indicates local access with low privileges and no user interaction.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.848 probability, 99.7th percentile), suggesting elevated near-term exploitation likelihood.
What to do
- Upgrade ClamAV to the fixed release referenced in the vendor advisory (1.3.0, 1.2.2, or 1.0.5) as the primary remediation.
- If VirusEvent is not required, remove or disable VirusEvent configuration options to eliminate the vulnerable code path.
- Run ClamAV under a dedicated, least-privilege service account with no unnecessary filesystem or network permissions.
- Restrict which users and processes can write files into directories that ClamAV scans, and sanitize or quarantine untrusted file names before scanning.
- Monitor vendor and distribution advisories for updated packages, since no workaround exists.
Detection
- Audit ClamAV configuration files for active VirusEvent directives and flag any host still using them.
- Monitor process trees for ClamAV spawning unexpected child processes or shells, which would indicate command injection.
- Alert on file names containing shell metacharacters (semicolons, backticks, $(), pipes) appearing in scanned directories.
- Review ClamAV service account activity for anomalous command execution or file writes outside its normal scan behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.clamav.net/2023/11/clamav-130-122-105-released.html | Release NotesVendor Advisory |
| https://blog.clamav.net/2023/11/clamav-130-122-105-released.html | Release NotesVendor Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/5FXZYVDNV66RNMNVJOHAJAYRZ |
Track CVE-2024-20328 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-20328), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.