← Vulnerability feed

Vulnerability record · CVE-2012-1454 · published 21 March 2012

CVE-2012-1454: Antivirus ELF parser malware detection bypass via modified ei_version

Aladdin · Esafe

Multiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by altering the ei_version field. An attacker can craft a malicious ELF binary that the scanner fails to flag, letting malware pass through the scanning layer. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser implementation.

4.3 CVSS 2.0 Medium EPSS 88% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw weakens malware detection across several widely deployed scanners, but CVSS is only 4.3 and there is no confirmed in-the-wild exploitation or KEV listing.

What it is

Multiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by altering the ei_version field. An attacker can craft a malicious ELF binary that the scanner fails to flag, letting malware pass through the scanning layer. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser implementation.

Impact

An attacker gains a way to deliver malware that evades detection by the listed antivirus engines, undermining the scanning control those products are meant to provide. The direct impact is integrity of the detection decision, not code execution in the scanner itself.

Attack surface

Reached remotely by submitting a crafted ELF file to a system that scans it with one of the affected products; no authentication is required per the AV:N/Au:N vector, though the attack is not automatic and depends on the file being processed. No user interaction is specified in the record.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.88234, 99.761st percentile), indicating strong predicted exploitation activity. No public exploit details are provided in the record.

What to do

  • Apply vendor updates for the affected antivirus and gateway products; the record does not list fixed versions, so confirm with each vendor.
  • Do not rely on a single affected scanner for ELF inspection; add a second engine or sandbox detonation for ELF files.
  • Block or quarantine inbound ELF files at mail and web gateways unless there is a documented business need.
  • Monitor vendor advisories for the possible split of this CVE into per-product identifiers and track each separately.

Detection

  • Alert on ELF files with unusual or inconsistent ei_version values reaching scanning infrastructure.
  • Correlate scanner verdicts with sandbox or secondary-engine results to find files that pass one engine but fail another.
  • Review gateway and mail logs for ELF attachments or downloads that were allowed through without a malware verdict.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1454 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12042Pandasecurity panda antivirus incorrect permission assignment vulnerabilityInsecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…EPSS 3.5%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5536Pandasecurity panda antivirus improper input validation vulnerabilityPanda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing…EPSS 2.8%7.2CVE-2009-4215Pandasecurity panda antivirus permissions and access controls vulnerabilityPanda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…EPSS 0.37%5.1CVE-2005-3221Fortinet antivirus vulnerabilityMultiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…EPSS 1.7%4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed4.3CVE-2012-1460Gzip parser in multiple antivirus engines allows malware detection bypassThe Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection…EPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1454), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.