CVE-2025-26790
Received Received - Intake

Remote Denial of Service in WithSecure Atlant with Capricorn Engine

Vulnerability report for CVE-2025-26790, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
withsecure atlant to 2025-01-20_02 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Remote Denial of Service (DoS) vulnerability in WithSecure Atlant with Capricorn engine before 2025-01-20_02. It occurs when the antivirus engine processes a document file, causing an out-of-bounds memory read that crashes the system remotely.

Detection Guidance

This vulnerability can be detected by checking the version of the Capricorn engine in WithSecure Atlant. If the version is before 2025-01-20_02, the system is vulnerable. Use the command 'withsecure --version' or check the antivirus engine logs for crashes during document file scans.

Impact Analysis

Exploiting this vulnerability could cause the antivirus engine to crash, leading to a denial of service. This means the system may become unresponsive or stop functioning properly during document scanning.

Mitigation Strategies

No immediate action is required as the fix has been distributed automatically through an update channel. Ensure your WithSecure Atlant product is updated to Capricorn version 2025-01-20_02 or later to mitigate the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-26790. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart