Vulnerability record · CVE-2012-1431 · published 21 March 2012
CVE-2012-1431: Antivirus ELF parsers bypassed by crafted file sequence
Aladdin · Esafe
Multiple antivirus products, including Bitdefender, McAfee Gateway, Sophos and others, fail to correctly parse ELF files containing a specific \4a\46\49\46 character sequence at a certain location. This lets a malicious ELF file evade malware detection by the affected scanners. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Description
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw enables detection bypass across many widely deployed antivirus products, but the CVSS impact is limited to integrity and no confirmed exploitation is documented.
What it is
Multiple antivirus products, including Bitdefender, McAfee Gateway, Sophos and others, fail to correctly parse ELF files containing a specific \4a\46\49\46 character sequence at a certain location. This lets a malicious ELF file evade malware detection by the affected scanners. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Impact
An attacker can deliver a malicious ELF binary that the affected antivirus engine does not flag, allowing malware to reach the target host undetected. The CVSS vector shows no confidentiality or availability impact, only a partial integrity impact.
Attack surface
Reached remotely over the network by submitting a crafted ELF file to a scanning service or gateway; no authentication is required. The vector AV:N/AC:M/Au:N indicates network reachability with medium attack complexity and no user interaction requirement stated.
Exploitation
Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is very high at 0.95998 (99.872 percentile), suggesting elevated predicted exploitation activity. No public exploit details are provided in the record.
What to do
- Apply vendor patches or updates for the affected antivirus and gateway products; check each vendor's advisory for the ELF parser fix.
- If no patch is available for a product, disable or restrict ELF scanning reliance and add a second detection layer such as YARA or a different engine.
- Block or quarantine inbound ELF files at the mail and web gateway until engines are confirmed fixed.
- Re-scan previously processed ELF files with an updated engine to catch any that bypassed detection.
- Track the NVD record for a possible CVE split and apply fixes per affected parser implementation.
Detection
- Monitor gateway and mail logs for ELF attachments or downloads that were allowed through without a malware verdict.
- Hunt for ELF files containing the byte sequence \4a\46\49\46 at the location described in the advisory.
- Compare detection results across multiple antivirus engines for the same ELF sample to spot engine-specific bypasses.
- Alert on endpoint execution of ELF binaries that arrived via email or web download and were not flagged by the installed scanner.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1431 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1431), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.