Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.165
EPSS Ranking 94.5%