Vulnerability record · CVE-2012-1429 · published 21 March 2012
CVE-2012-1429: Multiple antivirus ELF parsers allow malware detection bypass
Aladdin · Esafe
The ELF file parser in several antivirus products (Bitdefender, Comodo, Emsisoft, eSafe, F-Secure, Ikarus, McAfee, nProtect) mishandles an ELF file containing a ustar character sequence at a specific location. A crafted file can therefore evade malware detection by these scanners. The record notes the CVE may later be split if the flaw proves independent across parser implementations.
Description
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe bypass weakens malware detection but requires a crafted file and yields no direct code execution or data compromise on its own.
What it is
The ELF file parser in several antivirus products (Bitdefender, Comodo, Emsisoft, eSafe, F-Secure, Ikarus, McAfee, nProtect) mishandles an ELF file containing a ustar character sequence at a specific location. A crafted file can therefore evade malware detection by these scanners. The record notes the CVE may later be split if the flaw proves independent across parser implementations.
Impact
An attacker can deliver a malicious ELF file that the affected scanners fail to flag, allowing malware to reach a host that relies on these products for detection.
Attack surface
Reached remotely by supplying a crafted ELF file to a scanning engine, per the AV:N vector; no authentication is required, though the AC:M rating indicates some conditions must be met for a successful bypass.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.925, 99.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply vendor updates for the affected antivirus and scanning engine products; the record does not list fixed versions, so confirm with each vendor.
- Do not rely on a single affected scanner for ELF inspection; add a second, independent detection layer.
- Block or quarantine untrusted ELF binaries at email and web gateways until scanners are confirmed patched.
- Re-test detection of known-malicious ELF samples against current engine versions to verify the bypass is closed.
Detection
- Hunt for ELF files containing a ustar character sequence at the location described in the advisory.
- Monitor scanner logs for ELF files that pass inspection but later execute or trigger endpoint alerts.
- Compare detection results across multiple engines for the same ELF sample to spot single-engine misses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1429), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.