← Vulnerability feed

Vulnerability record · CVE-2012-1452 · published 21 March 2012

CVE-2012-1452: CAB parser malware detection bypass in Emsisoft, Ikarus and Quick Heal

Cat · Quick Heal

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 and Quick Heal 11.00 can be tricked into missing malicious content by modifying the reserved1 field of a CAB archive. Because the flaw defeats the core function of these security products, it lets malware pass through scanning undetected. The record notes it may later be split into separate CVEs if the error proves independent across the different parser implementations.

4.3 CVSS 2.0 Medium EPSS 89% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a CAB file with a modified reserved1 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than granting direct access, but it defeats a security control and carries a very high EPSS score, so it warrants prompt patching.

What it is

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 and Quick Heal 11.00 can be tricked into missing malicious content by modifying the reserved1 field of a CAB archive. Because the flaw defeats the core function of these security products, it lets malware pass through scanning undetected. The record notes it may later be split into separate CVEs if the error proves independent across the different parser implementations.

Impact

An attacker gains the ability to deliver malware inside a crafted CAB file that the affected scanners will not flag, undermining the protection the product is supposed to provide. There is no direct code execution or data modification on the scanning host described in the record.

Attack surface

The vector is network-reachable (AV:N) with no authentication required (Au:N), and the attack is delivered as a crafted CAB file that the target product parses. The CVSS 2.0 vector indicates medium complexity (AC:M), and the description does not state that user interaction is required.

Exploitation

The record shows no CISA KEV listing and no reference tags indicating public exploit code or active exploitation. EPSS is very high (0.88897, 99.769th percentile), suggesting elevated predicted exploitation activity, but this is a model estimate rather than confirmed exploitation.

What to do

  • Apply vendor updates for the affected Emsisoft, Ikarus and Quick Heal products; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix is available, supplement the affected scanner with a second, independently implemented anti-malware engine or gateway that parses CAB files differently.
  • Block or quarantine CAB archives from untrusted external sources at mail and web gateways until the parser is patched.
  • Re-scan historical quarantine and mail archives with an updated engine to catch samples that previously bypassed detection.
  • Track the NVD record for a possible CVE split, since fixes may be issued separately per vendor.

Detection

  • Monitor for CAB files whose reserved1 field is non-standard or altered, and alert on such files entering the environment.
  • Compare detection results between the affected scanner and a second engine on the same CAB samples to surface disagreements.
  • Review scanner and gateway logs for CAB attachments that were delivered but later identified as malicious by other tooling.
  • Hunt for inbound CAB archives from external senders or downloads that were not flagged by the primary AV engine.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1452 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%5.1CVE-2005-3231Cat quick heal vulnerabilityMultiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable …EPSS 14%5.0CVE-2005-3399Cat quick heal vulnerabilityMultiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…EPSS 7.8%4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed4.3CVE-2012-1459TAR parser malware detection bypass in multiple antivirus productsThe TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next en…EPSS 100%analysed4.3CVE-2012-1460Gzip parser in multiple antivirus engines allows malware detection bypassThe Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection…EPSS 94%analysed4.3CVE-2012-1462ZIP parser in multiple antivirus products allows malware detection bypassThe ZIP file parser in numerous antivirus and endpoint protection products mishandles a ZIP archive containing an invalid data block at the beginning…EPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1452), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.