← Vulnerability feed

Vulnerability record · CVE-2012-1450 · published 21 March 2012

CVE-2012-1450: CAB parser malware detection bypass in Emsisoft, Sophos and Ikarus scanners

Emsisoft · Anti Malware

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 can be evaded by a CAB file with a modified reserved3 field. A crafted archive is therefore not flagged as malicious, letting malware reach the host despite an up-to-date scanner. The record notes the issue may later be split into separate CVEs if the flaw proves independent across the three parsers.

4.3 CVSS 2.0 Medium EPSS 74% · top 0.5% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0, and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a modified reserved3 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw is a detection bypass rather than direct code execution, but it affects three widely deployed scanners and carries a very high EPSS score.

What it is

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 can be evaded by a CAB file with a modified reserved3 field. A crafted archive is therefore not flagged as malicious, letting malware reach the host despite an up-to-date scanner. The record notes the issue may later be split into separate CVEs if the flaw proves independent across the three parsers.

Impact

An attacker gains a detection bypass: malicious content inside a crafted CAB archive is not identified by the affected scanners, so the payload can be delivered to and executed on the protected system. There is no direct code execution or data compromise from the parser flaw itself; the gain is evasion of the security control.

Attack surface

The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N), so a crafted CAB file is delivered remotely, typically as an email attachment or download. No credentials are required; the only user action is opening or extracting the archive, which the description does not explicitly state but is implied by the file-based attack.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation. EPSS is high (0.73513 probability, 0.99442 percentile), indicating strong predicted likelihood of exploitation activity, but this is a model estimate, not observed evidence.

What to do

  • Apply vendor updates for Emsisoft Anti-Malware, Sophos Anti-Virus and Ikarus Virus Utilities T3 Command Line Scanner; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix exists, block or quarantine CAB attachments at the mail and web gateway and require out-of-band validation before extraction.
  • Add a second detection layer (different engine or sandbox detonation) for CAB archives so a single parser bypass does not equal delivery.
  • Restrict execution of files extracted from CAB archives via application control or mark-of-the-web style policy.
  • Monitor vendor advisories for the possible CVE split noted in the record, since remediation may need to be tracked per product.

Detection

  • Alert on inbound CAB files whose reserved3 header field deviates from the expected value, using a custom parser or YARA rule.
  • Correlate mail/web gateway logs for CAB attachments with endpoint execution of extracted binaries in the same session.
  • Hunt for scanner log entries where a CAB archive is passed as clean but a downstream sandbox or second engine flags it.
  • Review endpoint telemetry for processes spawned from temp or download directories shortly after a CAB file is written to disk.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6335Sophos anti-virus vulnerabilityMultiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive wit…EPSS 13%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.5CVE-2006-0994Sophos anti-virus vulnerabilityMultiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, …EPSS 22%7.5CVE-2005-2768Sophos anti-virus vulnerabilityHeap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote …EPSS 13%7.5CVE-2004-0937Archive zip vulnerabilitySophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…EPSS 15%7.5CVE-2004-0932McAfee Anti-Virus Engine DATS driver bypass via malformed compressed fileThe McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files…EPSS 63%analysed7.5CVE-2004-0933Archive zip vulnerabilityComputer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content M…EPSS 21%7.5CVE-2004-0934Archive zip vulnerabilityKaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whi…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2012-1450), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.