← Vulnerability feed

Vulnerability record · CVE-2012-1433 · published 21 March 2012

CVE-2012-1433: Multiple antivirus EXE parsers allow malware detection bypass

Ahnlab · V3 Internet Security

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) can be tricked by an EXE file containing a \4a\46\49\46 character sequence at a specific location. This causes the scanner to miss malware, undermining the core protection these tools provide. The record notes the issue may be split into separate CVEs if the flaw is later shown to be independent across parsers.

4.3 CVSS 2.0 Medium EPSS 94% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 base score is 4.3 (medium) and the flaw only bypasses detection, but the very high EPSS and the security-control nature of the bypass raise concern.

What it is

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) can be tricked by an EXE file containing a \4a\46\49\46 character sequence at a specific location. This causes the scanner to miss malware, undermining the core protection these tools provide. The record notes the issue may be split into separate CVEs if the flaw is later shown to be independent across parsers.

Impact

An attacker can deliver a malicious EXE that evades detection by the affected antivirus engines, allowing malware to run on a protected host. The direct gain is bypass of the security control, not code execution or data access by itself.

Attack surface

The flaw is reached remotely by supplying a crafted EXE file to the antivirus parser, typically as an email attachment, download, or file scan. No authentication is required, but some user action (opening or scanning the file) is likely needed for the parser to process it.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.93594, 99.8th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply vendor updates for the affected antivirus products as soon as they are available.
  • If no fix exists, replace or supplement the affected scanner with a product that parses EXE files correctly.
  • Block or quarantine EXE attachments at the email and web gateway until scanners are confirmed patched.
  • Verify detection by testing a known-malicious EXE with the \4a\46\49\46 sequence against the deployed scanner version.
  • Monitor vendor advisories for any CVE split that assigns separate fixes per product.

Detection

  • Search file submission and scan logs for EXE files containing the byte sequence \4a\46\49\46 at the parser-relevant offset.
  • Correlate endpoint telemetry for processes launched from EXE files that the antivirus reported as clean.
  • Alert on repeated antivirus scan misses for the same file hash across multiple hosts.
  • Review email and web gateway logs for EXE attachments that passed scanning but later executed suspicious behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1433 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2012-1433), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.