Vulnerability record · CVE-2012-1433 · published 21 March 2012
CVE-2012-1433: Multiple antivirus EXE parsers allow malware detection bypass
Ahnlab · V3 Internet Security
The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) can be tricked by an EXE file containing a \4a\46\49\46 character sequence at a specific location. This causes the scanner to miss malware, undermining the core protection these tools provide. The record notes the issue may be split into separate CVEs if the flaw is later shown to be independent across parsers.
Description
The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 base score is 4.3 (medium) and the flaw only bypasses detection, but the very high EPSS and the security-control nature of the bypass raise concern.
What it is
The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) can be tricked by an EXE file containing a \4a\46\49\46 character sequence at a specific location. This causes the scanner to miss malware, undermining the core protection these tools provide. The record notes the issue may be split into separate CVEs if the flaw is later shown to be independent across parsers.
Impact
An attacker can deliver a malicious EXE that evades detection by the affected antivirus engines, allowing malware to run on a protected host. The direct gain is bypass of the security control, not code execution or data access by itself.
Attack surface
The flaw is reached remotely by supplying a crafted EXE file to the antivirus parser, typically as an email attachment, download, or file scan. No authentication is required, but some user action (opening or scanning the file) is likely needed for the parser to process it.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.93594, 99.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply vendor updates for the affected antivirus products as soon as they are available.
- If no fix exists, replace or supplement the affected scanner with a product that parses EXE files correctly.
- Block or quarantine EXE attachments at the email and web gateway until scanners are confirmed patched.
- Verify detection by testing a known-malicious EXE with the \4a\46\49\46 sequence against the deployed scanner version.
- Monitor vendor advisories for any CVE split that assigns separate fixes per product.
Detection
- Search file submission and scan logs for EXE files containing the byte sequence \4a\46\49\46 at the parser-relevant offset.
- Correlate endpoint telemetry for processes launched from EXE files that the antivirus reported as clean.
- Alert on repeated antivirus scan misses for the same file hash across multiple hosts.
- Review email and web gateway logs for EXE attachments that passed scanning but later executed suspicious behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1433 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1433), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.