A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerability is due to unsafe handling of file names. A local attacker could exploit this vulnerability by supplying a file name containing command-line sequences. When processed on a system using configuration options for the VirusEvent feature, the attacker could cause the application to execute arbitrary commands. ClamAV has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Conclusion & alert: CVE-2024-20328 is rated Moderate Risk (40.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.31%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-20 | 0.25% | 0.31% | +0.07% |
| 2 | 2026-04-10 | 0.27% | 0.25% | -0.02% |
| 3 | 2026-03-27 | — | 0.27% | — |
Full EPSS history (36 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
1.8 | 3.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-20328: 1 source package rows (clamav); 9 state rows across 5 repos (3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 5, open 4. | https://security.alpinelinux.org/vuln/CVE-2024-20328 |
debian
|
unimportant | CVE-2024-20328 unimportant priority: Debian including 1 source packages (clamav), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-20328 |
gentoo
|
normal | CVE-2024-20328: 1 GLSA(s) (202507-03), 1 atom(s) (app-antivirus/clamav); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2024-20328 |
suse
|
high | CVE-2024-20328 severity important: SUSE including 10 source package names (clamav, clamav-devel, …), 137 product×package rows across 33 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7.1, … (33 product lines)): Known Not Affected 137. | https://www.suse.com/security/cve/CVE-2024-20328/ |
ubuntu
|
medium | CVE-2024-20328 medium priority: Ubuntu including 1 source packages (clamav), 8 status rows across 8 suites (bionic, focal, jammy, mantic, noble, trusty, upstream, xenial): not-affected 5, released 3. | https://ubuntu.com/security/CVE-2024-20328 |