Vulnerability record · CVE-2012-1451 · published 21 March 2012
CVE-2012-1451: Emsisoft and Ikarus CAB parser malware detection bypass
Emsisoft · Anti Malware
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 can be tricked by a CAB file with a modified reserved2 field. This lets a malicious CAB evade malware detection, so the scanner reports the file as clean while the payload remains intact.
Description
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a modified reserved2 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than granting code execution, but the high EPSS score and the security-control nature of the affected products raise the operational risk.
What it is
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 can be tricked by a CAB file with a modified reserved2 field. This lets a malicious CAB evade malware detection, so the scanner reports the file as clean while the payload remains intact.
Impact
An attacker can deliver a CAB file that bypasses the antivirus or command-line scanner, allowing malware to reach the target system without being flagged. The direct gain is evasion of detection, not code execution or privilege escalation.
Attack surface
The flaw is reached by supplying a crafted CAB file to the affected parser, typically as a file scanned or opened by the product. The CVSS vector AV:N/AC:M/Au:N indicates remote reachability with no authentication, but some user interaction or a medium-complexity condition is required.
Exploitation
No CISA KEV listing and no reference tags indicating public exploit code; EPSS is high at 0.67302 (99.268th percentile), suggesting elevated predicted exploitation activity despite the lack of confirmed in-the-wild use.
What to do
- Apply the vendor fix for the affected Emsisoft Anti-Malware and Ikarus T3 Command Line Scanner versions if one is available; if not, treat the products as unable to reliably detect crafted CAB files.
- Do not rely on the affected scanner as the sole control for CAB files; add a second detection layer such as a different engine, sandbox detonation, or file-type policy.
- Block or quarantine CAB files from untrusted sources at email and web gateways until the parser is fixed.
- Monitor vendor advisories for a possible CVE split or updated guidance, since the record notes the issue may be split across implementations.
Detection
- Hunt for CAB files with anomalous reserved2 field values and correlate them with files that the affected scanner marked clean.
- Review scanner logs for CAB files that were allowed through but later triggered alerts from other controls.
- Detonate or statically inspect CAB files in a sandbox before allowing them into the environment.
- Track EPSS and vendor advisories for this CVE and any split CVE identifiers covering the same parser behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1451 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1451), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.