← Vulnerability feed

Vulnerability record · CVE-2012-1444 · published 21 March 2012

CVE-2012-1444: Antivirus ELF parser malware detection bypass via modified abiversion field

Aladdin · Esafe

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 fails to properly handle a modified abiversion field, allowing malware to evade detection. This matters because a scanner that can be trivially bypassed provides false assurance and lets malicious ELF files reach the host undetected.

4.3 CVSS 2.0 Medium EPSS 63% · top 0.8% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS 2.0 rates this 4.3 (MEDIUM) with only integrity impact, but the very high EPSS percentile and the security-control bypass nature raise concern for environments still running these legacy scanners.

What it is

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 fails to properly handle a modified abiversion field, allowing malware to evade detection. This matters because a scanner that can be trivially bypassed provides false assurance and lets malicious ELF files reach the host undetected.

Impact

An attacker can deliver a malicious ELF file that the affected antivirus products will not flag, defeating the primary detection control on the endpoint or gateway. The attacker gains a reliable way to smuggle malware past these scanners.

Attack surface

The flaw is reached remotely by supplying a crafted ELF file to the affected scanning engine, as reflected in the AV:N vector. No authentication is required (Au:N), though the CVSS temporal metric AC:M indicates some conditions must be met for a successful bypass.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.63221 (99.169th percentile), suggesting elevated exploitation likelihood. The references carry no exploit tags, so no public exploit code is confirmed by this record.

What to do

  • Apply vendor updates for eSafe, Prevx, Fortinet Antivirus, and Panda Antivirus; if no fix exists, treat these versions as unreliable for ELF scanning.
  • Layer a second, independently maintained detection engine or sandbox for ELF files rather than relying on a single scanner.
  • Block or quarantine untrusted ELF files at email and web gateways until scanners are confirmed patched.
  • Restrict execution of ELF binaries on endpoints and servers to approved, signed sources.
  • Monitor vendor advisories because NVD notes this record may be split into separate CVEs per parser implementation.

Detection

  • Hunt for ELF files with unusual or non-standard abiversion values in file transfer and email logs.
  • Correlate endpoint execution of ELF binaries that were not flagged by the installed antivirus engine.
  • Review scanner logs for ELF files that pass inspection but later exhibit malicious behavior in sandbox or EDR telemetry.
  • Track which of the four affected products are deployed and verify their signature/engine versions against vendor fixes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1444 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%6.2CVE-2010-5174Prevx race condition vulnerabilityRace condition in Prevx 3.0.5.143 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwi…EPSS 0.29%5.1CVE-2005-3221Fortinet antivirus vulnerabilityMultiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…EPSS 1.7%4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1444), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.