← Vulnerability feed

Vulnerability record · CVE-2012-1440 · published 21 March 2012

CVE-2012-1440: Antivirus ELF parser malware detection bypass via modified identsize

Aladdin · Esafe

Multiple antivirus products (Norman, eSafe, CA eTrust Vet, Fortinet, Panda) parse ELF files in a way that can be tricked by a modified identsize field, allowing malware to evade detection. The flaw is a parser validation weakness rather than memory corruption, so it undermines the core protective function of the affected scanners.

4.3 CVSS 2.0 Medium EPSS 78% · top 0.4% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified identsize field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw weakens malware detection across several AV products but requires a crafted file and yields only evasion, with no KEV listing or confirmed in-the-wild exploit.

What it is

Multiple antivirus products (Norman, eSafe, CA eTrust Vet, Fortinet, Panda) parse ELF files in a way that can be tricked by a modified identsize field, allowing malware to evade detection. The flaw is a parser validation weakness rather than memory corruption, so it undermines the core protective function of the affected scanners.

Impact

An attacker can deliver a malicious ELF file that the affected antivirus engines fail to flag, letting malware reach the protected host undetected. There is no direct code execution or data modification from the flaw itself; the gain is evasion of the security control.

Attack surface

Reached remotely over the network when a crafted ELF file is scanned by the affected antivirus product, such as via email attachment, download, or file transfer. No authentication is required, but some user or system action to present the file for scanning is implied by the AV:N/AC:M vector.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, though EPSS is very high (0.777, 99.5th percentile). The references point to academic and mailing-list discussion rather than a weaponized exploit.

What to do

  • Apply vendor updates for the affected antivirus products; if no fix is available, treat the affected engine as unreliable for ELF scanning.
  • Layer detection with a second, independently maintained AV or EDR engine that parses ELF files differently.
  • Block or quarantine untrusted ELF binaries at email and web gateways before they reach endpoints.
  • Restrict execution of ELF binaries to trusted sources and monitor for unexpected ELF files on Linux hosts.
  • Re-scan historical quarantine and mail logs for ELF attachments that may have bypassed detection.

Detection

  • Hunt for ELF files with anomalous or inconsistent identsize values in file telemetry and sandbox submissions.
  • Alert on ELF binaries arriving via email attachments or web downloads that were not flagged by the primary AV engine.
  • Correlate AV scan results with sandbox detonation outcomes to find files that pass scanning but exhibit malicious behavior.
  • Monitor for execution of newly written ELF files in user-writable directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1440 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5535Norman antivirus \& antispyware improper input validation vulnerabilityNorman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placin…EPSS 3.0%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%5.1CVE-2005-3221Fortinet antivirus vulnerabilityMultiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…EPSS 1.7%4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1440), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.