← Vulnerability feed

Vulnerability record · CVE-2012-1448 · published 21 March 2012

CVE-2012-1448: CAB parser malware detection bypass in multiple antivirus products

Cat · Quick Heal

The CAB file parser in Quick Heal 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 can be tricked by a CAB file with a modified cbCabinet field. This lets a crafted archive evade malware scanning, so malicious content inside the CAB may reach the user undetected. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser.

4.3 CVSS 2.0 Medium EPSS 89% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The CAB file parser in Quick Heal (aka Cat QuickHeal) 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 allows remote attackers to bypass malware detection via a CAB file with a modified cbCabinet field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than granting code execution, but it affects widely used antivirus products and has a very high EPSS score.

What it is

The CAB file parser in Quick Heal 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 can be tricked by a CAB file with a modified cbCabinet field. This lets a crafted archive evade malware scanning, so malicious content inside the CAB may reach the user undetected. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser.

Impact

An attacker can bypass malware detection and deliver a CAB archive that the affected scanner treats as clean. The gain is evasion of the antivirus check, not code execution or data access on the scanning host.

Attack surface

Reached remotely by supplying a crafted CAB file to the affected scanner, for example through a scan of a downloaded or emailed archive. The CVSS vector AV:N/AC:M/Au:N indicates network delivery with no authentication, but some user action such as opening or scanning the file is likely required.

Exploitation

Not listed in CISA KEV, and the references carry no exploit tags. EPSS is high (0.88856, 99.768th percentile), but that score reflects general interest rather than confirmed in-the-wild exploitation of this specific bypass.

What to do

  • Apply vendor updates for the affected antivirus and scanner products; if no fix is available, treat the CAB parser as untrusted.
  • Add a second detection layer (different engine or sandbox) for CAB archives rather than relying on the affected scanner alone.
  • Block or quarantine CAB files from untrusted sources at the mail gateway and web proxy.
  • Verify the cbCabinet field and overall CAB structure with an independent parser before trusting a clean scan result.

Detection

  • Alert on CAB files whose cbCabinet header value is inconsistent with the actual cabinet structure or file size.
  • Correlate scan results across multiple engines and flag CAB archives that one engine passes while another flags.
  • Monitor for repeated delivery of CAB archives from the same source that produce no detection on the affected products.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1448 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-38764Trendmicro housecall incorrect default permissions vulnerabilityA vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissiv…EPSS 0.22%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%5.1CVE-2005-3231Cat quick heal vulnerabilityMultiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable …EPSS 14%5.0CVE-2005-3399Cat quick heal vulnerabilityMultiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…EPSS 7.8%4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed4.3CVE-2012-1459TAR parser malware detection bypass in multiple antivirus productsThe TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next en…EPSS 100%analysed4.3CVE-2012-1460Gzip parser in multiple antivirus engines allows malware detection bypassThe Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection…EPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1448), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.