← Vulnerability feed

Vulnerability record · CVE-2012-1432 · published 21 March 2012

CVE-2012-1432: Multiple antivirus EXE parsers allow malware detection bypass

Aladdin · Esafe

The EXE file parser in Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus can be tricked into skipping malware detection when an EXE file contains the byte sequence \57\69\6E\5A\69\70 at a specific location. This lets a malicious executable evade scanning by these products, undermining the core protection they provide. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser.

4.3 CVSS 2.0 Medium EPSS 93% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The Microsoft EXE file parser in Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 is 4.3 (MEDIUM) and the flaw only bypasses detection, but the very high EPSS score and multiple affected security products raise defensive concern.

What it is

The EXE file parser in Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus can be tricked into skipping malware detection when an EXE file contains the byte sequence \57\69\6E\5A\69\70 at a specific location. This lets a malicious executable evade scanning by these products, undermining the core protection they provide. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser.

Impact

An attacker can deliver an EXE that these antivirus products fail to flag as malicious, allowing malware to run on a protected host. The direct gain is evasion of detection, not code execution or privilege escalation by itself.

Attack surface

The vector is network-reachable (AV:N) with medium attack complexity and no authentication required (Au:N). The attacker supplies a crafted EXE file that is parsed by the affected antivirus product; no user interaction is described beyond the file being scanned.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.93402, 99.834th percentile), indicating a strong likelihood of exploitation activity. The references are conference and mailing-list posts with no exploit tags, so no confirmed public exploit is documented in this record.

What to do

  • Apply vendor updates for Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus; if no fix exists, treat the affected parser as unreliable.
  • Do not rely on the affected EXE parser as the sole malware detection layer; add independent endpoint detection and file reputation checks.
  • Block or quarantine untrusted EXE files at email and web gateways before they reach hosts protected only by these products.
  • Monitor vendor advisories for the possible CVE split and track each affected product separately.

Detection

  • Hunt for EXE files containing the byte sequence \57\69\6E\5A\69\70 at the parser-relevant location and correlate with files that the affected antivirus did not flag.
  • Compare antivirus verdicts against a second scanning engine or sandbox for EXE files entering the environment.
  • Alert on execution of EXE files that passed the affected antivirus but are flagged by EDR or reputation services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1432 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed4.3CVE-2012-1459TAR parser malware detection bypass in multiple antivirus productsThe TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next en…EPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1432), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.