Vulnerability record · CVE-2012-1449 · published 21 March 2012
CVE-2012-1449: NOD32 and Rising Antivirus CAB parser malware detection bypass
Eset · Nod32 Antivirus
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into missing malicious content by modifying the vMajor field of a CAB archive. This lets a crafted archive evade on-access or on-demand scanning, undermining the core protection these products provide. The record notes it may later be split if the flaw proves independent across the two parsers.
Description
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMajor field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses malware detection rather than granting direct access, but the high EPSS score and the security-critical nature of antivirus evasion keep it above low.
What it is
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into missing malicious content by modifying the vMajor field of a CAB archive. This lets a crafted archive evade on-access or on-demand scanning, undermining the core protection these products provide. The record notes it may later be split if the flaw proves independent across the two parsers.
Impact
An attacker gains a way to deliver malware inside a CAB archive that the affected antivirus engines fail to flag, so the payload can reach the endpoint unscanned. There is no direct code execution or data modification from the parser flaw itself; the gain is evasion of detection.
Attack surface
The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N), so a crafted CAB file can be delivered by any normal channel such as email, download or web. No credentials are needed, but some user action to open or receive the file is implied by the medium complexity rating.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, though EPSS is high at 0.6113 (99.1st percentile), suggesting elevated predicted exploitation activity. No ransomware association is documented.
What to do
- Apply the vendor fixes for NOD32 Antivirus and Rising Antivirus; if no patch is available for these 2012-era versions, upgrade to a currently supported release.
- Block or quarantine CAB archives at the mail gateway and web proxy until engines are confirmed patched.
- Enable layered detection (behavioral, reputation and sandbox analysis) so a missed signature does not mean a missed infection.
- Restrict execution of files extracted from archives via application control or endpoint policy.
- Re-scan historical CAB attachments with an updated engine to catch samples that previously bypassed detection.
Detection
- Monitor for CAB files with unusual or inconsistent vMajor header values in email and web traffic.
- Alert on archive extraction followed by process creation from user-writable directories.
- Hunt for antivirus scan logs showing CAB files passed as clean that later execute or drop payloads.
- Correlate endpoint telemetry for child processes spawned from archive-handling applications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1449 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.