← Vulnerability feed

Vulnerability record · CVE-2009-1348 · published 30 April 2009

CVE-2009-1348: Mcafee active virus defense improper input validation vulnerability

MMcafee · Active Virus Defense

The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.

7.6 CVSS 2.0 High EPSS 2.8% · top 13.9% CWE-20 · Improper input validation
7.6CVSS 2.0 base score
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2013-7103Mcafee email gateway os command injection vulnerabilityMcAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in …EPSS 3.9%9.0CVE-2013-7104Mcafee email gateway os command injection vulnerabilityMcAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) …EPSS 3.9%8.5CVE-2013-6349Mcafee email gateway code injection vulnerabilityMcAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vect…EPSS 2.5%7.5CVE-2012-4595Mcafee email and web security improper authentication vulnerabilityMcAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attack…EPSS 2.5%7.2CVE-2005-1107Mcafee internet security suite vulnerabilityMcAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection…EPSS 0.34%6.8CVE-2012-4581Mcafee email and web security improper authentication vulnerabilityMcAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disabl…EPSS 1.2%6.8CVE-2006-3961Mcafee antispyware memory buffer overflow vulnerabilityBuffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network S…EPSS 34%6.5CVE-2016-8005Mcafee email gateway permissions and access controls vulnerabilityFile extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the f…EPSS 0.72%

Source: NIST National Vulnerability Database (record CVE-2009-1348), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.