Vulnerability record · CVE-2012-1452 · published 21 March 2012
CVE-2012-1452: CAB parser malware detection bypass in Emsisoft, Ikarus and Quick Heal
Cat · Quick Heal
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 and Quick Heal 11.00 can be tricked into missing malicious content by modifying the reserved1 field of a CAB archive. Because the flaw defeats the core function of these security products, it lets malware pass through scanning undetected. The record notes it may later be split into separate CVEs if the error proves independent across the different parser implementations.
Description
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a CAB file with a modified reserved1 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than granting direct access, but it defeats a security control and carries a very high EPSS score, so it warrants prompt patching.
What it is
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 and Quick Heal 11.00 can be tricked into missing malicious content by modifying the reserved1 field of a CAB archive. Because the flaw defeats the core function of these security products, it lets malware pass through scanning undetected. The record notes it may later be split into separate CVEs if the error proves independent across the different parser implementations.
Impact
An attacker gains the ability to deliver malware inside a crafted CAB file that the affected scanners will not flag, undermining the protection the product is supposed to provide. There is no direct code execution or data modification on the scanning host described in the record.
Attack surface
The vector is network-reachable (AV:N) with no authentication required (Au:N), and the attack is delivered as a crafted CAB file that the target product parses. The CVSS 2.0 vector indicates medium complexity (AC:M), and the description does not state that user interaction is required.
Exploitation
The record shows no CISA KEV listing and no reference tags indicating public exploit code or active exploitation. EPSS is very high (0.88897, 99.769th percentile), suggesting elevated predicted exploitation activity, but this is a model estimate rather than confirmed exploitation.
What to do
- Apply vendor updates for the affected Emsisoft, Ikarus and Quick Heal products; the record does not list fixed versions, so confirm with each vendor.
- Where no fix is available, supplement the affected scanner with a second, independently implemented anti-malware engine or gateway that parses CAB files differently.
- Block or quarantine CAB archives from untrusted external sources at mail and web gateways until the parser is patched.
- Re-scan historical quarantine and mail archives with an updated engine to catch samples that previously bypassed detection.
- Track the NVD record for a possible CVE split, since fixes may be issued separately per vendor.
Detection
- Monitor for CAB files whose reserved1 field is non-standard or altered, and alert on such files entering the environment.
- Compare detection results between the affected scanner and a second engine on the same CAB samples to surface disagreements.
- Review scanner and gateway logs for CAB attachments that were delivered but later identified as malicious by other tooling.
- Hunt for inbound CAB archives from external senders or downloads that were not flagged by the primary AV engine.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1452 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1452), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.