← Vulnerability feed

Vulnerability record · CVE-2004-0932 · published 27 January 2005

CVE-2004-0932: McAfee Anti-Virus Engine DATS driver bypass via malformed compressed file

Archive Zip · Archive Zip

The McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files whose local and global headers are both set to zero. Such a file can still be opened on the target system, so the antivirus engine does not block it, allowing malicious content to pass through scanning. This matters because it undermines the core protection of the affected antivirus products.

7.5 CVSS 2.0 High EPSS 63% · top 0.8%
7.5CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
23Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated antivirus bypass with public exploit references and very high EPSS, though it is not in KEV and the record lacks modern affected-version detail.

What it is

The McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files whose local and global headers are both set to zero. Such a file can still be opened on the target system, so the antivirus engine does not block it, allowing malicious content to pass through scanning. This matters because it undermines the core protection of the affected antivirus products.

Impact

An attacker can deliver a compressed archive that evades antivirus detection and is opened on the target, potentially leading to code execution or other compromise depending on the payload inside. The flaw weakens the antivirus layer rather than directly granting access by itself.

Attack surface

Reachable remotely over the network with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/Au:N). The attack is delivered as a crafted compressed file processed by the vulnerable antivirus engine.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.66 (99.2nd percentile), and SecurityFocus references are tagged Exploit, Patch and Vendor Advisory, indicating public exploit information exists.

What to do

  • Update McAfee Anti-Virus Engine DATS drivers to 4398 or later (or DATS Driver to 4397 or later) as released in October 2004.
  • Apply the vendor patch referenced in the SecurityFocus advisory for affected products.
  • For other listed vendors (CA, ESET, Kaspersky, RAV, Sophos, Gentoo, Mandrake, SuSE), apply their corresponding fixes for this shared archive-handling issue.
  • Where patching is not immediately possible, block or quarantine compressed archives with zeroed local and global headers at the mail or gateway layer.

Detection

  • Inspect compressed archive files for local and global headers both set to zero and flag them for manual review.
  • Monitor antivirus engine logs for archives that were opened but not scanned or blocked.
  • Hunt for inbound compressed attachments or transfers that bypass AV verdicts and reach endpoints.
  • Correlate gateway and endpoint AV logs for discrepancies between files received and files scanned.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0932 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0042Broadcom anti-spyware vulnerabilityMultiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterpr…EPSS 4.3%10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-2241Broadcom brightstor arcserve backup path traversal vulnerabilityDirectory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data…EPSS 12%10.0CVE-2007-5325Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r1…EPSS 12%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5327Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityStack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Ente…EPSS 16%10.0CVE-2007-5328Broadcom brightstor arcserve backup permissions and access controls vulnerabilityThe Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…EPSS 7.0%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2004-0932), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.