← Vulnerability feed

Vulnerability record · CVE-2012-1453 · published 21 March 2012

CVE-2012-1453: CAB parser malware detection bypass in multiple antivirus products

Antiy · Avl Sdk

The CAB file parser in numerous antivirus and security products mishandles the coffFiles field, allowing a crafted CAB archive to evade malware detection. Because the affected component is the scanner itself, a malicious file can pass inspection while remaining intact for later execution. The record covers many independent vendor implementations and may later be split into separate CVEs.

4.3 CVSS 2.0 Medium EPSS 98% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
14Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe flaw weakens malware detection across many widely deployed security products, but it requires a crafted file and yields evasion rather than direct compromise, and no confirmed exploitation is recorded.

What it is

The CAB file parser in numerous antivirus and security products mishandles the coffFiles field, allowing a crafted CAB archive to evade malware detection. Because the affected component is the scanner itself, a malicious file can pass inspection while remaining intact for later execution. The record covers many independent vendor implementations and may later be split into separate CVEs.

Impact

An attacker gains the ability to deliver malware inside a CAB archive that the affected scanner fails to flag, undermining the primary defense layer. No direct code execution or data modification is attributed to the flaw itself; the gain is evasion of detection.

Attack surface

Reachable remotely over the network by supplying a crafted CAB file to a system whose antivirus or gateway product parses it. No authentication is required, though some user interaction (opening or downloading the file) is implied by the AV:N/AC:M vector.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.9771, 99.9th percentile), but the references carry no exploit tags, so public exploit code is not confirmed by this record.

What to do

  • Apply vendor updates for each affected antivirus, gateway and endpoint product; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix exists, disable or restrict CAB archive scanning reliance and block CAB attachments at mail and web gateways.
  • Add independent detection layers (sandboxing, file reputation, YARA) so a single parser bypass does not equal full evasion.
  • Inventory which of the listed products and versions are deployed and prioritize internet-facing gateway and mail scanners.
  • Treat CAB files from untrusted sources as suspicious and inspect them with a second, non-affected engine.

Detection

  • Alert on CAB files whose coffFiles field is malformed or inconsistent with the archive structure.
  • Monitor for files that pass AV scanning but later spawn processes or write executables.
  • Correlate gateway logs showing CAB attachments with endpoint execution events.
  • Hunt for repeated submissions of CAB samples that different engines classify inconsistently.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1453 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%5.1CVE-2005-3221Fortinet antivirus vulnerabilityMultiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…EPSS 1.7%4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed4.3CVE-2012-1459TAR parser malware detection bypass in multiple antivirus productsThe TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next en…EPSS 100%analysed4.3CVE-2012-1460Gzip parser in multiple antivirus engines allows malware detection bypassThe Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection…EPSS 94%analysed4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1461Gzip parser in multiple antivirus products allows malware detection bypassThe Gzip file parser in numerous antivirus and anti-malware products mishandles .tar.gz files containing multiple compressed streams, allowing a craf…EPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1453), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.