← Vulnerability feed

Vulnerability record · CVE-2012-1430 · published 21 March 2012

CVE-2012-1430: Multiple antivirus ELF parsers allow malware detection bypass

Aladdin · Esafe

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 fails to correctly handle an ELF file containing a \19\04\00\10 character sequence at a certain location. A crafted file can therefore evade malware detection by these engines. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 96% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses malware detection (CVSS 4.3, integrity impact only) and has no confirmed exploitation, though the very high EPSS and broad product list warrant attention.

What it is

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 fails to correctly handle an ELF file containing a \19\04\00\10 character sequence at a certain location. A crafted file can therefore evade malware detection by these engines. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

Impact

An attacker can deliver a malicious ELF file that the affected antivirus products fail to flag, allowing malware to reach a host that relies on these engines for scanning. The direct gain is detection bypass, not code execution or privilege escalation.

Attack surface

Reached remotely over the network by supplying a crafted ELF file to a scanning engine, as reflected in the AV:N vector. No authentication is required (Au:N), but the CVSS temporal-style AC:M indicates some conditions must be met for the bypass to succeed; no user interaction is stated in the record.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code. EPSS is very high (0.95998, 99.873rd percentile), suggesting elevated predicted exploitation activity, but the record provides no confirmed in-the-wild evidence.

What to do

  • Apply vendor updates for the affected antivirus and gateway products; the record does not list fixed versions, so confirm with each vendor.
  • Do not rely on a single affected engine for ELF scanning; add a second, independent detection layer.
  • Restrict or inspect ELF file transfers at network and email gateways, since the bypass is delivered as a file.
  • Where the affected product is end-of-life or unsupported, migrate to a maintained scanning engine.
  • Monitor vendor advisories for the possible CVE split, which may change which products are in scope.

Detection

  • Hunt for ELF files containing the byte sequence 19 04 00 10 at the location described, and submit them to multiple engines for comparison.
  • Compare detection verdicts across engines on the same ELF sample to surface disagreements consistent with this bypass.
  • Alert on ELF files arriving through email or web channels where the environment normally expects only Windows executables.
  • Track scanning engine versions in the environment against the affected product list to find unpatched instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1430 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5409Bitdefender antivirus memory buffer overflow vulnerabilityUnspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, an…EPSS 11%9.3CVE-2008-0470Comodo antivirus vulnerabilityA certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.EPSS 31%7.5CVE-2013-7369F-secure anti-virus sql injection vulnerabilitySQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, An…EPSS 1.3%6.8CVE-2009-1782F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier…EPSS 2.2%6.4CVE-2010-3499F-secure anti-virus permissions and access controls vulnerabilityF-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for…EPSS 2.6%5.0CVE-2010-1425F-secure anti-virus vulnerabilityF-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeep…EPSS 2.2%4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1430), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.