Vulnerability record · CVE-2004-0932 · published 27 January 2005
CVE-2004-0932: McAfee Anti-Virus Engine DATS driver bypass via malformed compressed file
Archive Zip · Archive Zip
The McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files whose local and global headers are both set to zero. Such a file can still be opened on the target system, so the antivirus engine does not block it, allowing malicious content to pass through scanning. This matters because it undermines the core protection of the affected antivirus products.
Description
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated antivirus bypass with public exploit references and very high EPSS, though it is not in KEV and the record lacks modern affected-version detail.
What it is
The McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files whose local and global headers are both set to zero. Such a file can still be opened on the target system, so the antivirus engine does not block it, allowing malicious content to pass through scanning. This matters because it undermines the core protection of the affected antivirus products.
Impact
An attacker can deliver a compressed archive that evades antivirus detection and is opened on the target, potentially leading to code execution or other compromise depending on the payload inside. The flaw weakens the antivirus layer rather than directly granting access by itself.
Attack surface
Reachable remotely over the network with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/Au:N). The attack is delivered as a crafted compressed file processed by the vulnerable antivirus engine.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.66 (99.2nd percentile), and SecurityFocus references are tagged Exploit, Patch and Vendor Advisory, indicating public exploit information exists.
What to do
- Update McAfee Anti-Virus Engine DATS drivers to 4398 or later (or DATS Driver to 4397 or later) as released in October 2004.
- Apply the vendor patch referenced in the SecurityFocus advisory for affected products.
- For other listed vendors (CA, ESET, Kaspersky, RAV, Sophos, Gentoo, Mandrake, SuSE), apply their corresponding fixes for this shared archive-handling issue.
- Where patching is not immediately possible, block or quarantine compressed archives with zeroed local and global headers at the mail or gateway layer.
Detection
- Inspect compressed archive files for local and global headers both set to zero and flag them for manual review.
- Monitor antivirus engine logs for archives that were opened but not scanned or blocked.
- Hunt for inbound compressed attachments or transfers that bypass AV verdicts and reach endpoints.
- Correlate gateway and endpoint AV logs for discrepancies between files received and files scanned.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0932 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0932), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.