← Vulnerability feed

Vulnerability record · CVE-2012-1442 · published 21 March 2012

CVE-2012-1442: Multiple antivirus ELF parsers allow malware detection bypass via modified class field

Aladdin · Esafe

The ELF file parser in numerous antivirus products (Quick Heal, McAfee, eSafe, Kaspersky, F-Secure, Sophos, Antiy AVL SDK, Rising, Fortinet, Panda) mishandles the ELF class field, letting a crafted ELF file evade malware detection. Because these engines sit in the scanning path for email, web and file transfers, a bypass undermines the core protection they provide. The record notes it may later be split into separate CVEs if the flaw proves independent across implementations.

4.3 CVSS 2.0 Medium EPSS 99% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, Antiy Labs AVL SDK 2.0.3.7, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified class field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe bypass weakens malware detection across many widely deployed scanners, but it grants no direct code execution and CVSS rates it only 4.3.

What it is

The ELF file parser in numerous antivirus products (Quick Heal, McAfee, eSafe, Kaspersky, F-Secure, Sophos, Antiy AVL SDK, Rising, Fortinet, Panda) mishandles the ELF class field, letting a crafted ELF file evade malware detection. Because these engines sit in the scanning path for email, web and file transfers, a bypass undermines the core protection they provide. The record notes it may later be split into separate CVEs if the flaw proves independent across implementations.

Impact

An attacker can deliver a malicious ELF binary that the affected scanners fail to flag, allowing malware to reach the endpoint or pass through a gateway undetected. The flaw itself gives no code execution or data access; the gain is evasion of detection.

Attack surface

Reached remotely by supplying a crafted ELF file to a system or gateway running one of the listed scanning engines, per the AV:N vector. No authentication is required (Au:N), though the CVSS AC:M rating implies some conditions must be met for the bypass to succeed.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.98917, 99.9th percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply vendor updates for each affected antivirus/scanning engine; treat the listed versions as the affected baseline and confirm fixed builds with each vendor.
  • Where no fix is available, disable or restrict ELF scanning reliance for untrusted sources and add a second detection layer (sandboxing, YARA, or endpoint behavioral controls).
  • Block or quarantine inbound ELF files at mail and web gateways unless explicitly required by business need.
  • Monitor vendor advisories for the possible CVE split, since individual products may receive separate fixes and severity ratings.

Detection

  • Hunt for ELF files with inconsistent or unusual class field values (e.g., class byte not matching expected 32/64-bit layout) arriving via email or web downloads.
  • Correlate gateway scan logs showing clean verdicts with subsequent endpoint execution of ELF binaries from external sources.
  • Alert on ELF files delivered to Windows-centric environments where ELF execution is unexpected.
  • Track vendor patch levels for the listed scanning engines and flag hosts still running the affected versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1442 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2967F-secure anti-virus improper input validation vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scann…EPSS 4.8%10.0CVE-2006-6409F-secure anti-virus vulnerabilityF-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass vir…EPSS 3.7%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2007-3300F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header …EPSS 3.7%7.6CVE-2008-6085F-secure anti-virus vulnerabilityInteger overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, w…EPSS 5.5%7.6CVE-2006-2838F-secure anti-virus vulnerabilityBuffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remo…EPSS 5.7%7.5CVE-2008-0910F-secure anti-virus permissions and access controls vulnerabilityMultiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2012-1442), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.