Corrupted-Header Archive Weaponizing ClamAV Parser Flaws (CVE-2025-8088, CVE-2026-20337/38)
On August 7, 2026, ClamAV 1.5.4 / 1.4.6 shipped fixes for eight high-risk flaws in its ZIP, GPT, PDF, Mach-O, and XAR parsers — several of which can crash the scan service outright. The most severe, CVE-2025-8088 in the UnRAR library (CVSS 8.2), plus two flaws with public proof-of-concept code (CVE-2026-20337, CVE-2026-20338), put every single-engine scanner at risk: one malformed archive header is enough to knock out the only engine in the pipeline and let the file pass. Cisco's advisory confirms the impact on Secure Endpoint Connector deployments (High on Windows). This demo ships a .docx — itself a ZIP container — whose local file header magic has been deliberately corrupted (the PK signature replaced) to emulate the malformed-archive pattern that triggers parser weaknesses in single-engine products. OPSWAT MetaDefender's FileType Engine ignores the broken surface header and recovers the true file type from structural content, and the 30+ engine Multiscan pipeline means a flaw in any one parser — including ClamAV itself — never decides the verdict on its own.
Attack Technique
Malformed archive header exploiting parser flaws (single-engine scan evasion)
MITRE ATT&CK
T1027.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗