CVE-2023-20052 is an XML external entity injection vulnerability in the DMG file parser of ClamAV. It affects ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier. The issue is caused by XML entity substitution being enabled during parsing, which allows external entities to be resolved when a crafted DMG file is scanned. By submitting a malicious DMG file to an affected ClamAV instance, an unauthenticated remote attacker can trigger the parser to read local resources accessible to the ClamAV scanning process and disclose their contents.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone proof-of-concept exploit for CVE-2023-20052 in ClamAV. It contains two files: a README with usage notes and one executable script, exploit.sh, which is the sole entry point. The script is not a scanner or detector; it automates creation of a malicious DMG file intended to exploit an XXE-style parsing issue in ClamAV's handling of DMG/plist metadata. The exploit flow is: prompt the operator for a target file path to read, clone the libdmg-hfsplus project from GitHub, build its dmg utility inside a Docker multi-stage build, generate a benign DMG from a small source directory, copy the resulting DMG out of the container, and then patch the DMG bytes using embedded Python. The Python code searches the DMG for an XML plist header, replaces it with a crafted DOCTYPE containing an external entity declaration pointing to file://<TARGET_FILE>, and modifies a blkx token to blkx&xxe; so the entity is referenced during parsing. The final output is exploit.dmg. Main capability: arbitrary local file read from the system running vulnerable ClamAV, if that system scans or parses the crafted DMG. The exploit does not include exfiltration, reverse shell, persistence, or remote command execution; it is focused on generating a malicious file artifact that triggers file disclosure during antivirus processing. Because it produces a working malicious payload but with a fixed/basic technique and no flexible delivery framework, the maturity is best classified as OPERATIONAL.
This repository provides a proof-of-concept (POC) exploit for CVE-2023-20052, an information leak vulnerability in the DMG file parser of ClamAV. The repository contains a Dockerfile that sets up an Ubuntu-based environment with all necessary tools to build and manipulate DMG files, including cloning and compiling the 'libdmg-hfsplus' utility. The README.md provides step-by-step instructions to create a malicious DMG file: a normal DMG is generated, then modified using 'bbe' to inject an XXE payload into the plist, referencing '/etc/passwd'. When this crafted DMG is scanned by ClamAV, the XXE is triggered, causing ClamAV to leak the contents of the targeted file. The exploit is local in nature, requiring the attacker to supply the malicious DMG to a system running ClamAV. The repository does not contain any direct exploit code, but provides the environment and commands necessary to generate the payload. No network C2 or remote endpoints are involved, but several URLs and file paths are fingerprintable from the Dockerfile and documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.