---
id: CVE-2020-37167
title: "ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the\_ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names"
summary: "ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the\_ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation …"
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: ClamAV
product: ClamBC
affected:
  - ClamBC < 0.103.0-rc
published: '2026-02-12'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:17:52.143'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37167'
references:
  - url: >-
      https://github.com/Cisco-Talos/clamav/commit/cd2f2975b93277de7f74464d48adb378375a305f
    label: disclosure@vulncheck.com
  - url: 'https://www.clamav.net/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/47687'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/clamav-clambc-clambc-executable-regular-expression-error
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00179
epssPercentile: 0.06683
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-02-13T17:08:35.606676Z'
ingestedAt: '2026-09-30T18:17:24.568Z'
---

## Overview

ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
