← Vulnerability feed

Vulnerability record · CVE-2012-1429 · published 21 March 2012

CVE-2012-1429: Multiple antivirus ELF parsers allow malware detection bypass

Aladdin · Esafe

The ELF file parser in several antivirus products (Bitdefender, Comodo, Emsisoft, eSafe, F-Secure, Ikarus, McAfee, nProtect) mishandles an ELF file containing a ustar character sequence at a specific location. A crafted file can therefore evade malware detection by these scanners. The record notes the CVE may later be split if the flaw proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 92% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe bypass weakens malware detection but requires a crafted file and yields no direct code execution or data compromise on its own.

What it is

The ELF file parser in several antivirus products (Bitdefender, Comodo, Emsisoft, eSafe, F-Secure, Ikarus, McAfee, nProtect) mishandles an ELF file containing a ustar character sequence at a specific location. A crafted file can therefore evade malware detection by these scanners. The record notes the CVE may later be split if the flaw proves independent across parser implementations.

Impact

An attacker can deliver a malicious ELF file that the affected scanners fail to flag, allowing malware to reach a host that relies on these products for detection.

Attack surface

Reached remotely by supplying a crafted ELF file to a scanning engine, per the AV:N vector; no authentication is required, though the AC:M rating indicates some conditions must be met for a successful bypass.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.925, 99.8th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply vendor updates for the affected antivirus and scanning engine products; the record does not list fixed versions, so confirm with each vendor.
  • Do not rely on a single affected scanner for ELF inspection; add a second, independent detection layer.
  • Block or quarantine untrusted ELF binaries at email and web gateways until scanners are confirmed patched.
  • Re-test detection of known-malicious ELF samples against current engine versions to verify the bypass is closed.

Detection

  • Hunt for ELF files containing a ustar character sequence at the location described in the advisory.
  • Monitor scanner logs for ELF files that pass inspection but later execute or trigger endpoint alerts.
  • Compare detection results across multiple engines for the same ELF sample to spot single-engine misses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2967F-secure anti-virus improper input validation vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scann…EPSS 4.8%10.0CVE-2006-6409F-secure anti-virus vulnerabilityF-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass vir…EPSS 3.7%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-0470Comodo antivirus vulnerabilityA certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.EPSS 31%9.3CVE-2007-3300F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header …EPSS 3.7%7.6CVE-2008-6085F-secure anti-virus vulnerabilityInteger overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, w…EPSS 5.5%7.6CVE-2006-2838F-secure anti-virus vulnerabilityBuffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remo…EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2012-1429), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.