← Vulnerability feed

Vulnerability record · CVE-2012-1435 · published 21 March 2012

CVE-2012-1435: Antivirus EXE parsers bypassed via crafted PKLITE marker

Ahnlab · V3 Internet Security

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) can be tricked into missing malware by placing a \50\4B\4C\49\54\45 ("PKLITE") character sequence at a specific location in an EXE file. This lets a malicious executable evade detection, undermining the core protective function of the affected scanners.

4.3 CVSS 2.0 Medium EPSS 94% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 is 4.3 (MEDIUM) and impact is limited to detection bypass, but the very high EPSS score and the security-critical nature of antivirus parsers raise concern.

What it is

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) can be tricked into missing malware by placing a \50\4B\4C\49\54\45 ("PKLITE") character sequence at a specific location in an EXE file. This lets a malicious executable evade detection, undermining the core protective function of the affected scanners.

Impact

An attacker can deliver an EXE that the affected antivirus engines fail to flag, allowing malware to run on a protected host. The gain is detection bypass, not direct code execution or privilege escalation.

Attack surface

Reached remotely over the network by supplying a crafted EXE file to the scanner (AV:N, AC:M, Au:N per CVSS 2.0). No authentication is required; user interaction is not specified in the record.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high (0.93594, 99.8th percentile), indicating strong predicted exploitation activity.

What to do

  • Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix is available, replace or supplement the affected scanner with an engine that correctly parses the PKLITE marker.
  • Block or quarantine EXE files containing the \50\4B\4C\49\54\45 sequence at the parser-relevant offset at the mail and web gateway.
  • Reduce reliance on a single AV engine for EXE inspection; add sandbox detonation or second-opinion scanning.
  • Monitor vendor advisories for a possible CVE split, since the record notes the issue may be separated per parser implementation.

Detection

  • Scan inbound and stored EXE files for the byte sequence 50 4B 4C 49 54 45 at the location referenced in the parser logic.
  • Alert on EXE files that pass AV clean but exhibit packing or PKLITE-style markers inconsistent with their declared type.
  • Correlate endpoint execution of EXE files that were not flagged by the installed AV engine with subsequent suspicious behavior.
  • Review AV engine version inventory to identify hosts still running the affected builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1435 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2012-1435), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.