← Vulnerability feed

Vulnerability record · CVE-2012-1434 · published 21 March 2012

CVE-2012-1434: Malware scanners bypassed by crafted EXE parser input

Ahnlab · V3 Internet Security

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus) fails to correctly handle an EXE file containing a specific byte sequence (\19\04\00\10) at a certain location. This lets a crafted executable evade malware detection, undermining the core protective function of the affected scanners. The record notes the issue may later be split into separate CVEs if the parsers are shown to fail independently.

4.3 CVSS 2.0 Medium EPSS 60% · top 0.9% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityIt is a detection bypass in antivirus products with no confirmed in-the-wild exploitation and only medium CVSS impact, but the high EPSS score and the defensive nature of the affected software warrant prompt patching.

What it is

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, Ikarus Virus Utilities T3 Command Line Scanner, and Panda Antivirus) fails to correctly handle an EXE file containing a specific byte sequence (\19\04\00\10) at a certain location. This lets a crafted executable evade malware detection, undermining the core protective function of the affected scanners. The record notes the issue may later be split into separate CVEs if the parsers are shown to fail independently.

Impact

An attacker can deliver a malicious EXE that the affected antivirus engines do not flag, allowing malware to reach and execute on a protected host. The direct gain is detection bypass rather than code execution or privilege escalation by itself.

Attack surface

Reached remotely over the network by supplying a crafted EXE file to a system running one of the affected scanners; no authentication is required per the CVSS vector (AV:N/Au:N). Some user interaction is implied by AC:M, likely opening or scanning the file.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high (0.60076, ~99th percentile), indicating elevated predicted exploitation activity despite the absence of confirmed in-the-wild reports.

What to do

  • Apply vendor updates for the affected antivirus products; treat the listed versions as the only confirmed affected builds and verify current fixed releases with each vendor.
  • Layer detection: do not rely on a single scanner for EXE inspection; use multiple engines or a sandbox for untrusted executables.
  • Block or quarantine untrusted EXE attachments and downloads at the email and web gateway before endpoint scanning.
  • Restrict execution of unsigned or untrusted binaries via application allowlisting where feasible.
  • Monitor vendor advisories for a possible CVE split, since the record warns the issue may be divided across parser implementations.

Detection

  • Hunt for EXE files containing the byte sequence 19 04 00 10 at the parser-relevant offset and submit them to multiple engines for comparison.
  • Compare scan verdicts across engines on the same EXE to surface files that one scanner misses and another flags.
  • Alert on executables that pass endpoint AV but later exhibit malicious behavior (process creation, network callbacks) from user-writable paths.
  • Track EPSS and vendor advisories for this CVE family to catch renewed exploitation interest.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1434 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1434), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.