Vulnerability record · CVE-2012-1454 · published 21 March 2012
CVE-2012-1454: Antivirus ELF parser malware detection bypass via modified ei_version
Aladdin · Esafe
Multiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by altering the ei_version field. An attacker can craft a malicious ELF binary that the scanner fails to flag, letting malware pass through the scanning layer. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser implementation.
Description
The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw weakens malware detection across several widely deployed scanners, but CVSS is only 4.3 and there is no confirmed in-the-wild exploitation or KEV listing.
What it is
Multiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by altering the ei_version field. An attacker can craft a malicious ELF binary that the scanner fails to flag, letting malware pass through the scanning layer. The record notes it may later be split into separate CVEs if the flaw is confirmed independently in each parser implementation.
Impact
An attacker gains a way to deliver malware that evades detection by the listed antivirus engines, undermining the scanning control those products are meant to provide. The direct impact is integrity of the detection decision, not code execution in the scanner itself.
Attack surface
Reached remotely by submitting a crafted ELF file to a system that scans it with one of the affected products; no authentication is required per the AV:N/Au:N vector, though the attack is not automatic and depends on the file being processed. No user interaction is specified in the record.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.88234, 99.761st percentile), indicating strong predicted exploitation activity. No public exploit details are provided in the record.
What to do
- Apply vendor updates for the affected antivirus and gateway products; the record does not list fixed versions, so confirm with each vendor.
- Do not rely on a single affected scanner for ELF inspection; add a second engine or sandbox detonation for ELF files.
- Block or quarantine inbound ELF files at mail and web gateways unless there is a documented business need.
- Monitor vendor advisories for the possible split of this CVE into per-product identifiers and track each separately.
Detection
- Alert on ELF files with unusual or inconsistent ei_version values reaching scanning infrastructure.
- Correlate scanner verdicts with sandbox or secondary-engine results to find files that pass one engine but fail another.
- Review gateway and mail logs for ELF attachments or downloads that were allowed through without a malware verdict.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1454 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1454), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.