← Vulnerability feed

Vulnerability record · CVE-2012-1436 · published 21 March 2012

CVE-2012-1436: Malware scanners bypassed by crafted EXE byte sequence

Ahnlab · V3 Internet Security

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) fails to correctly handle an EXE file containing a \2D\6C\68 character sequence at a certain location. A remote attacker can craft a malicious executable that the scanner does not flag, defeating the core protection these products provide. The record notes the issue may later be split into separate CVEs if the parsers are shown to fail independently.

4.3 CVSS 2.0 Medium EPSS 94% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw undermines malware detection across multiple AV products, but it requires a crafted file and medium attack complexity, and there is no confirmed in-the-wild exploitation or KEV listing.

What it is

The EXE file parser in several antivirus products (AhnLab V3 Internet Security, Emsisoft Anti-Malware, eSafe, Ikarus Virus Utilities T3, Panda Antivirus) fails to correctly handle an EXE file containing a \2D\6C\68 character sequence at a certain location. A remote attacker can craft a malicious executable that the scanner does not flag, defeating the core protection these products provide. The record notes the issue may later be split into separate CVEs if the parsers are shown to fail independently.

Impact

An attacker gains the ability to deliver malware that passes undetected through the affected scanners, leaving the endpoint's primary defense ineffective. The CVSS vector shows no confidentiality or availability impact, only a partial integrity impact.

Attack surface

Reached remotely over the network by supplying a crafted EXE file to the scanner; no authentication is required, though the CVSS vector notes medium attack complexity. No user interaction is specified in the record.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.93594, 99.8th percentile), suggesting elevated predicted exploitation activity. The record does not confirm in-the-wild use.

What to do

  • Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm patched builds with each vendor.
  • Layer detection with a second, independent scanning engine or endpoint detection tool so a single parser bypass does not leave the host unprotected.
  • Block or quarantine executables from untrusted sources at the mail and web gateway rather than relying solely on endpoint AV.
  • Monitor vendor advisories for the possible CVE split, which may require tracking separate fixes per product.

Detection

  • Hunt for EXE files containing the \2D\6C\68 byte sequence at the parser-relevant offset and correlate with files that later execute or persist.
  • Alert on executables that pass AV scanning but are subsequently flagged by a second engine or by behavioral EDR rules.
  • Review AV scan logs for executables that were scanned without detection yet later spawned suspicious child processes or network connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1436 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2012-1436), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.