Vulnerability record · CVE-2012-1448 · published 21 March 2012
CVE-2012-1448: CAB parser malware detection bypass in multiple antivirus products
Cat · Quick Heal
The CAB file parser in Quick Heal 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 can be tricked by a CAB file with a modified cbCabinet field. This lets a crafted archive evade malware scanning, so malicious content inside the CAB may reach the user undetected. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser.
Description
The CAB file parser in Quick Heal (aka Cat QuickHeal) 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 allows remote attackers to bypass malware detection via a CAB file with a modified cbCabinet field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than granting code execution, but it affects widely used antivirus products and has a very high EPSS score.
What it is
The CAB file parser in Quick Heal 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 can be tricked by a CAB file with a modified cbCabinet field. This lets a crafted archive evade malware scanning, so malicious content inside the CAB may reach the user undetected. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser.
Impact
An attacker can bypass malware detection and deliver a CAB archive that the affected scanner treats as clean. The gain is evasion of the antivirus check, not code execution or data access on the scanning host.
Attack surface
Reached remotely by supplying a crafted CAB file to the affected scanner, for example through a scan of a downloaded or emailed archive. The CVSS vector AV:N/AC:M/Au:N indicates network delivery with no authentication, but some user action such as opening or scanning the file is likely required.
Exploitation
Not listed in CISA KEV, and the references carry no exploit tags. EPSS is high (0.88856, 99.768th percentile), but that score reflects general interest rather than confirmed in-the-wild exploitation of this specific bypass.
What to do
- Apply vendor updates for the affected antivirus and scanner products; if no fix is available, treat the CAB parser as untrusted.
- Add a second detection layer (different engine or sandbox) for CAB archives rather than relying on the affected scanner alone.
- Block or quarantine CAB files from untrusted sources at the mail gateway and web proxy.
- Verify the cbCabinet field and overall CAB structure with an independent parser before trusting a clean scan result.
Detection
- Alert on CAB files whose cbCabinet header value is inconsistent with the actual cabinet structure or file size.
- Correlate scan results across multiple engines and flag CAB archives that one engine passes while another flags.
- Monitor for repeated delivery of CAB archives from the same source that produce no detection on the affected products.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1448 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1448), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.