Vulnerability record · CVE-2012-1430 · published 21 March 2012
CVE-2012-1430: Multiple antivirus ELF parsers allow malware detection bypass
Aladdin · Esafe
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 fails to correctly handle an ELF file containing a \19\04\00\10 character sequence at a certain location. A crafted file can therefore evade malware detection by these engines. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Description
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses malware detection (CVSS 4.3, integrity impact only) and has no confirmed exploitation, though the very high EPSS and broad product list warrant attention.
What it is
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 fails to correctly handle an ELF file containing a \19\04\00\10 character sequence at a certain location. A crafted file can therefore evade malware detection by these engines. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Impact
An attacker can deliver a malicious ELF file that the affected antivirus products fail to flag, allowing malware to reach a host that relies on these engines for scanning. The direct gain is detection bypass, not code execution or privilege escalation.
Attack surface
Reached remotely over the network by supplying a crafted ELF file to a scanning engine, as reflected in the AV:N vector. No authentication is required (Au:N), but the CVSS temporal-style AC:M indicates some conditions must be met for the bypass to succeed; no user interaction is stated in the record.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code. EPSS is very high (0.95998, 99.873rd percentile), suggesting elevated predicted exploitation activity, but the record provides no confirmed in-the-wild evidence.
What to do
- Apply vendor updates for the affected antivirus and gateway products; the record does not list fixed versions, so confirm with each vendor.
- Do not rely on a single affected engine for ELF scanning; add a second, independent detection layer.
- Restrict or inspect ELF file transfers at network and email gateways, since the bypass is delivered as a file.
- Where the affected product is end-of-life or unsupported, migrate to a maintained scanning engine.
- Monitor vendor advisories for the possible CVE split, which may change which products are in scope.
Detection
- Hunt for ELF files containing the byte sequence 19 04 00 10 at the location described, and submit them to multiple engines for comparison.
- Compare detection verdicts across engines on the same ELF sample to surface disagreements consistent with this bypass.
- Alert on ELF files arriving through email or web channels where the environment normally expects only Windows executables.
- Track scanning engine versions in the environment against the affected product list to find unpatched instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1430 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1430), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.