github.compatch
https://github.com/Cisco-Talos/clamav/commit/cd2f2975b93277de7f74464d48adb378375a305f CVE-2020-37167
HIGH
ClamAV ClamBC < 0.103.0-rc - 'ClamBC' Executable Regular Expression Error
Record summary
CVE-2020-37167 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ClamBCBrowse ClamAV / ClamBCDefault status: unknown | CVE List | Before 0.103.0-rc | unaffected |
Proofs of concept
1Catalogued exploits
ExploitDBClamAV < 0.102.0 - 'bytecode_vm' Code ExecutionExploitDB exploitby anonymousNot analyzed1 file
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37167 clamav.netproduct
https://www.clamav.net/ ExploitDB-47687exploit
https://www.exploit-db.com/exploits/47687 vulncheck.com
https://www.vulncheck.com/advisories/clamav-clambc-clambc-executable-regular-expression vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/clamav-clambc-clambc-executable-regular-expression-error