Vulnerability record · CVE-2012-1453 · published 21 March 2012
CVE-2012-1453: CAB parser malware detection bypass in multiple antivirus products
Antiy · Avl Sdk
The CAB file parser in numerous antivirus and security products mishandles the coffFiles field, allowing a crafted CAB archive to evade malware detection. Because the affected component is the scanner itself, a malicious file can pass inspection while remaining intact for later execution. The record covers many independent vendor implementations and may later be split into separate CVEs.
Description
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw weakens malware detection across many widely deployed security products, but it requires a crafted file and yields evasion rather than direct compromise, and no confirmed exploitation is recorded.
What it is
The CAB file parser in numerous antivirus and security products mishandles the coffFiles field, allowing a crafted CAB archive to evade malware detection. Because the affected component is the scanner itself, a malicious file can pass inspection while remaining intact for later execution. The record covers many independent vendor implementations and may later be split into separate CVEs.
Impact
An attacker gains the ability to deliver malware inside a CAB archive that the affected scanner fails to flag, undermining the primary defense layer. No direct code execution or data modification is attributed to the flaw itself; the gain is evasion of detection.
Attack surface
Reachable remotely over the network by supplying a crafted CAB file to a system whose antivirus or gateway product parses it. No authentication is required, though some user interaction (opening or downloading the file) is implied by the AV:N/AC:M vector.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.9771, 99.9th percentile), but the references carry no exploit tags, so public exploit code is not confirmed by this record.
What to do
- Apply vendor updates for each affected antivirus, gateway and endpoint product; the record does not list fixed versions, so confirm with each vendor.
- Where no fix exists, disable or restrict CAB archive scanning reliance and block CAB attachments at mail and web gateways.
- Add independent detection layers (sandboxing, file reputation, YARA) so a single parser bypass does not equal full evasion.
- Inventory which of the listed products and versions are deployed and prioritize internet-facing gateway and mail scanners.
- Treat CAB files from untrusted sources as suspicious and inspect them with a second, non-affected engine.
Detection
- Alert on CAB files whose coffFiles field is malformed or inconsistent with the archive structure.
- Monitor for files that pass AV scanning but later spawn processes or write executables.
- Correlate gateway logs showing CAB attachments with endpoint execution events.
- Hunt for repeated submissions of CAB samples that different engines classify inconsistently.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1453 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1453), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.