← Vulnerability feed

Vulnerability record · CVE-2012-1431 · published 21 March 2012

CVE-2012-1431: Antivirus ELF parsers bypassed by crafted file sequence

Aladdin · Esafe

Multiple antivirus products, including Bitdefender, McAfee Gateway, Sophos and others, fail to correctly parse ELF files containing a specific \4a\46\49\46 character sequence at a certain location. This lets a malicious ELF file evade malware detection by the affected scanners. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 96% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw enables detection bypass across many widely deployed antivirus products, but the CVSS impact is limited to integrity and no confirmed exploitation is documented.

What it is

Multiple antivirus products, including Bitdefender, McAfee Gateway, Sophos and others, fail to correctly parse ELF files containing a specific \4a\46\49\46 character sequence at a certain location. This lets a malicious ELF file evade malware detection by the affected scanners. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

Impact

An attacker can deliver a malicious ELF binary that the affected antivirus engine does not flag, allowing malware to reach the target host undetected. The CVSS vector shows no confidentiality or availability impact, only a partial integrity impact.

Attack surface

Reached remotely over the network by submitting a crafted ELF file to a scanning service or gateway; no authentication is required. The vector AV:N/AC:M/Au:N indicates network reachability with medium attack complexity and no user interaction requirement stated.

Exploitation

Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is very high at 0.95998 (99.872 percentile), suggesting elevated predicted exploitation activity. No public exploit details are provided in the record.

What to do

  • Apply vendor patches or updates for the affected antivirus and gateway products; check each vendor's advisory for the ELF parser fix.
  • If no patch is available for a product, disable or restrict ELF scanning reliance and add a second detection layer such as YARA or a different engine.
  • Block or quarantine inbound ELF files at the mail and web gateway until engines are confirmed fixed.
  • Re-scan previously processed ELF files with an updated engine to catch any that bypassed detection.
  • Track the NVD record for a possible CVE split and apply fixes per affected parser implementation.

Detection

  • Monitor gateway and mail logs for ELF attachments or downloads that were allowed through without a malware verdict.
  • Hunt for ELF files containing the byte sequence \4a\46\49\46 at the location described in the advisory.
  • Compare detection results across multiple antivirus engines for the same ELF sample to spot engine-specific bypasses.
  • Alert on endpoint execution of ELF binaries that arrived via email or web download and were not flagged by the installed scanner.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1431 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1783F-prot antivirus improper input validation vulnerabilityMultiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Se…EPSS 3.4%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5409Bitdefender antivirus memory buffer overflow vulnerabilityUnspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, an…EPSS 11%9.3CVE-2008-0470Comodo antivirus vulnerabilityA certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.EPSS 31%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%7.5CVE-2006-6293F-prot antivirus memory buffer overflow vulnerabilityHeap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a craf…EPSS 16%5.0CVE-2008-5747F-prot antivirus vulnerabilityF-Prot 4.6.8 for GNU/Linux allows remote attackers to bypass anti-virus protection via a crafted ELF program with a "corrupted" header that still all…EPSS 3.1%5.0CVE-2008-3447F-prot antivirus vulnerabilityThe scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, …EPSS 7.9%

Source: NIST National Vulnerability Database (record CVE-2012-1431), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.