← Vulnerability feed

Vulnerability record · CVE-2012-1447 · published 21 March 2012

CVE-2012-1447: Antivirus ELF parser detection bypass via modified e_version field

Aladdin · Esafe

The ELF file parser in Fortinet Antivirus, eSafe, Dr.Web and Panda Antivirus fails to properly handle a modified e_version field, allowing a crafted ELF file to evade malware detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes it may later be split into separate CVEs if the flaw proves independent across the different parser implementations.

4.3 CVSS 2.0 Medium EPSS 68% · top 0.7% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified e_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than granting direct access, but it affects widely deployed AV engines and carries a high EPSS score.

What it is

The ELF file parser in Fortinet Antivirus, eSafe, Dr.Web and Panda Antivirus fails to properly handle a modified e_version field, allowing a crafted ELF file to evade malware detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes it may later be split into separate CVEs if the flaw proves independent across the different parser implementations.

Impact

An attacker can deliver a malicious ELF file that the antivirus engine does not flag, letting malware reach the target host undetected. The direct gain is evasion of detection rather than code execution or data access.

Attack surface

Reachable remotely over the network by supplying a crafted ELF file to the scanning engine; no authentication is required. The CVSS vector indicates medium attack complexity and no user interaction requirement, though in practice a file must be scanned or opened.

Exploitation

Not listed in CISA KEV, and no reference is tagged as exploit or proof-of-concept. EPSS is high (0.67655, 99.3rd percentile), suggesting elevated predicted exploitation activity despite the absence of confirmed public exploit code.

What to do

  • Apply vendor updates for the affected antivirus products; no fixed version is stated in this record, so confirm with each vendor.
  • Do not rely on a single AV engine for ELF files; add a second, independently implemented scanner or sandbox detonation.
  • Block or quarantine untrusted ELF binaries at email and web gateways before they reach endpoint scanners.
  • Restrict execution of ELF binaries to trusted sources and monitor for files with anomalous e_version header values.

Detection

  • Hunt for ELF files with non-standard or modified e_version header values in scan logs and file repositories.
  • Correlate AV scan results with sandbox or second-engine verdicts to find files that one engine misses.
  • Monitor for ELF binaries arriving via email or web download that pass AV but exhibit suspicious behavior.
  • Review AV engine version inventory to identify hosts still running the affected parser builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%5.1CVE-2005-3221Fortinet antivirus vulnerabilityMultiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…EPSS 1.7%4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1447), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.