← Vulnerability feed

Vulnerability record · CVE-2009-1782 · published 22 May 2009

CVE-2009-1782: F-secure anti-virus vulnerability

F Secure · Anti Virus

Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.

6.8 CVSS 2.0 Medium EPSS 2.2% · top 18.1%
6.8CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1782 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2967F-secure anti-virus improper input validation vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scann…EPSS 4.8%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2007-3300F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header …EPSS 3.7%8.8CVE-2021-33601F-secure internet gatekeeper vulnerabilityA vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web u…EPSS 0.94%7.8CVE-2023-43766F-secure linux protection improper privilege management vulnerabilityCertain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecu…EPSS 0.16%7.8CVE-2019-11644F-secure client security uncontrolled search path element vulnerabilityIn the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure…EPSS 1.5%7.6CVE-2006-2838F-secure anti-virus vulnerabilityBuffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remo…EPSS 5.7%7.5CVE-2023-49322F-secure linux protection vulnerabilityCertain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects…EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2009-1782), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.