← Vulnerability feed

Vulnerability record · CVE-2012-1449 · published 21 March 2012

CVE-2012-1449: NOD32 and Rising Antivirus CAB parser malware detection bypass

Eset · Nod32 Antivirus

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into missing malicious content by modifying the vMajor field of a CAB archive. This lets a crafted archive evade on-access or on-demand scanning, undermining the core protection these products provide. The record notes it may later be split if the flaw proves independent across the two parsers.

4.3 CVSS 2.0 Medium EPSS 61% · top 0.9% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMajor field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses malware detection rather than granting direct access, but the high EPSS score and the security-critical nature of antivirus evasion keep it above low.

What it is

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into missing malicious content by modifying the vMajor field of a CAB archive. This lets a crafted archive evade on-access or on-demand scanning, undermining the core protection these products provide. The record notes it may later be split if the flaw proves independent across the two parsers.

Impact

An attacker gains a way to deliver malware inside a CAB archive that the affected antivirus engines fail to flag, so the payload can reach the endpoint unscanned. There is no direct code execution or data modification from the parser flaw itself; the gain is evasion of detection.

Attack surface

The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N), so a crafted CAB file can be delivered by any normal channel such as email, download or web. No credentials are needed, but some user action to open or receive the file is implied by the medium complexity rating.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, though EPSS is high at 0.6113 (99.1st percentile), suggesting elevated predicted exploitation activity. No ransomware association is documented.

What to do

  • Apply the vendor fixes for NOD32 Antivirus and Rising Antivirus; if no patch is available for these 2012-era versions, upgrade to a currently supported release.
  • Block or quarantine CAB archives at the mail gateway and web proxy until engines are confirmed patched.
  • Enable layered detection (behavioral, reputation and sandbox analysis) so a missed signature does not mean a missed infection.
  • Restrict execution of files extracted from archives via application control or endpoint policy.
  • Re-scan historical CAB attachments with an updated engine to catch samples that previously bypassed detection.

Detection

  • Monitor for CAB files with unusual or inconsistent vMajor header values in email and web traffic.
  • Alert on archive extraction followed by process creation from user-writable directories.
  • Hunt for antivirus scan logs showing CAB files passed as clean that later execute or drop payloads.
  • Correlate endpoint telemetry for child processes spawned from archive-handling applications.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1449 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10180Eset cyber security interpretation conflict vulnerabilityThe ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart S…EPSS 1.7%9.3CVE-2008-5539Rising-global rising antivirus improper input validation vulnerabilityRISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware …EPSS 10%9.3CVE-2008-5534Eset nod32 antivirus improper input validation vulnerabilityESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML…EPSS 3.5%8.6CVE-2023-5594Eset endpoint antivirus improper certificate validation vulnerabilityImproper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …EPSS 0.38%7.8CVE-2024-0353Eset endpoint antivirus improper privilege management vulnerabilityLocal privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…EPSS 0.55%7.8CVE-2021-37851Eset endpoint antivirus vulnerabilityLocal privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run ma…EPSS 0.21%7.8CVE-2021-37852Eset endpoint antivirus improper privilege management vulnerabilityESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …EPSS 0.60%7.8CVE-2020-11446Eset antivirus and antispyware link following vulnerabilityESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2012-1449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.