← Vulnerability feed

Vulnerability record · CVE-2012-1445 · published 21 March 2012

CVE-2012-1445: Antivirus ELF parser malware detection bypass via modified abi field

Aladdin · Esafe

The ELF file parser in eSafe, Rising Antivirus, Fortinet Antivirus and Panda Antivirus can be tricked into misreading an ELF file when its abi field is modified, allowing malware to evade detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes the issue may later be split if the error proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 90% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abi field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 scores it 4.3 (MEDIUM) with integrity-only impact, but the high EPSS and the fact that it defeats antivirus detection raise defensive concern.

What it is

The ELF file parser in eSafe, Rising Antivirus, Fortinet Antivirus and Panda Antivirus can be tricked into misreading an ELF file when its abi field is modified, allowing malware to evade detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes the issue may later be split if the error proves independent across parser implementations.

Impact

An attacker can deliver a malicious ELF file that the affected antivirus engine fails to flag, letting malware reach a host that otherwise relies on that scanner. The direct gain is evasion of detection, not code execution or data access on its own.

Attack surface

The flaw is reached remotely by supplying a crafted ELF file to the scanning engine, for example through file transfer, email attachment or on-access scanning. No authentication is required, though the CVSS vector indicates medium attack complexity and no user interaction is specified.

Exploitation

No CISA KEV listing and no reference tags indicating public exploit code; EPSS is very high (0.89938, 99.786th percentile), suggesting elevated predicted exploitation activity despite the absence of confirmed in-the-wild use.

What to do

  • Apply vendor updates for eSafe, Rising Antivirus, Fortinet Antivirus and Panda Antivirus; if no fix exists, treat these versions as unable to reliably detect crafted ELF files.
  • Layer a second, independent detection engine or sandbox for ELF files rather than relying on a single affected scanner.
  • Block or quarantine ELF files at email and web gateways where they are not operationally required.
  • Monitor vendor advisories for the possible split of this CVE into per-product identifiers and track each separately.

Detection

  • Hunt for ELF files with unusual or modified abi field values reaching endpoints or mail gateways.
  • Correlate scanner logs for ELF files that pass clean but later execute or trigger endpoint alerts.
  • Alert on ELF file transfers to hosts that do not normally handle Linux binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1445 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5539Rising-global rising antivirus improper input validation vulnerabilityRISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware …EPSS 10%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.2CVE-2010-1591Rising-global rising antivirus improper input validation vulnerabilityBeijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allow…EPSS 1.6%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%5.1CVE-2005-3221Fortinet antivirus vulnerabilityMultiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…EPSS 1.7%4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1445), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.