Vulnerability record · CVE-2012-1434 · published 21 March 2012
CVE-2012-1434: Malware scanners bypassed by crafted EXE parser input
Ahnlab · V3 Internet Security
The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus) fails to correctly handle an EXE file containing a specific byte sequence (\19\04\00\10) at a certain location. This lets a crafted executable evade malware detection, undermining the core protective function of the affected scanners. The record notes the issue may later be split into separate CVEs if the parsers are shown to fail independently.
Description
The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityIt is a detection bypass in antivirus products with no confirmed in-the-wild exploitation and only medium CVSS impact, but the high EPSS score and the defensive nature of the affected software warrant prompt patching.
What it is
The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus) fails to correctly handle an EXE file containing a specific byte sequence (\19\04\00\10) at a certain location. This lets a crafted executable evade malware detection, undermining the core protective function of the affected scanners. The record notes the issue may later be split into separate CVEs if the parsers are shown to fail independently.
Impact
An attacker can deliver a malicious EXE that the affected antivirus engines do not flag, allowing malware to reach and execute on a protected host. The direct gain is detection bypass rather than code execution or privilege escalation by itself.
Attack surface
Reached remotely over the network by supplying a crafted EXE file to a system running one of the affected scanners; no authentication is required per the CVSS vector (AV:N/Au:N). Some user interaction is implied by AC:M, likely opening or scanning the file.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high (0.60076, ~99th percentile), indicating elevated predicted exploitation activity despite the absence of confirmed in-the-wild reports.
What to do
- Apply vendor updates for the affected antivirus products; treat the listed versions as the only confirmed affected builds and verify current fixed releases with each vendor.
- Layer detection: do not rely on a single scanner for EXE inspection; use multiple engines or a sandbox for untrusted executables.
- Block or quarantine untrusted EXE attachments and downloads at the email and web gateway before endpoint scanning.
- Restrict execution of unsigned or untrusted binaries via application allowlisting where feasible.
- Monitor vendor advisories for a possible CVE split, since the record warns the issue may be divided across parser implementations.
Detection
- Hunt for EXE files containing the byte sequence 19 04 00 10 at the parser-relevant offset and submit them to multiple engines for comparison.
- Compare scan verdicts across engines on the same EXE to surface files that one scanner misses and another flags.
- Alert on executables that pass endpoint AV but later exhibit malicious behavior (process creation, network callbacks) from user-writable paths.
- Track EPSS and vendor advisories for this CVE family to catch renewed exploitation interest.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1434 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1434), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.