Vulnerability record · CVE-2012-1450 · published 21 March 2012
CVE-2012-1450: CAB parser malware detection bypass in Emsisoft, Sophos and Ikarus scanners
Emsisoft · Anti Malware
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 can be evaded by a CAB file with a modified reserved3 field. A crafted archive is therefore not flagged as malicious, letting malware reach the host despite an up-to-date scanner. The record notes the issue may later be split into separate CVEs if the flaw proves independent across the three parsers.
Description
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0, and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a modified reserved3 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is a detection bypass rather than direct code execution, but it affects three widely deployed scanners and carries a very high EPSS score.
What it is
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 can be evaded by a CAB file with a modified reserved3 field. A crafted archive is therefore not flagged as malicious, letting malware reach the host despite an up-to-date scanner. The record notes the issue may later be split into separate CVEs if the flaw proves independent across the three parsers.
Impact
An attacker gains a detection bypass: malicious content inside a crafted CAB archive is not identified by the affected scanners, so the payload can be delivered to and executed on the protected system. There is no direct code execution or data compromise from the parser flaw itself; the gain is evasion of the security control.
Attack surface
The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N), so a crafted CAB file is delivered remotely, typically as an email attachment or download. No credentials are required; the only user action is opening or extracting the archive, which the description does not explicitly state but is implied by the file-based attack.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation. EPSS is high (0.73513 probability, 0.99442 percentile), indicating strong predicted likelihood of exploitation activity, but this is a model estimate, not observed evidence.
What to do
- Apply vendor updates for Emsisoft Anti-Malware, Sophos Anti-Virus and Ikarus Virus Utilities T3 Command Line Scanner; the record does not list fixed versions, so confirm with each vendor.
- Where no fix exists, block or quarantine CAB attachments at the mail and web gateway and require out-of-band validation before extraction.
- Add a second detection layer (different engine or sandbox detonation) for CAB archives so a single parser bypass does not equal delivery.
- Restrict execution of files extracted from CAB archives via application control or mark-of-the-web style policy.
- Monitor vendor advisories for the possible CVE split noted in the record, since remediation may need to be tracked per product.
Detection
- Alert on inbound CAB files whose reserved3 header field deviates from the expected value, using a custom parser or YARA rule.
- Correlate mail/web gateway logs for CAB attachments with endpoint execution of extracted binaries in the same session.
- Hunt for scanner log entries where a CAB archive is passed as clean but a downstream sandbox or second engine flags it.
- Review endpoint telemetry for processes spawned from temp or download directories shortly after a CAB file is written to disk.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1450 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1450), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.