← Vulnerability feed

Vulnerability record · CVE-2012-1455 · published 21 March 2012

CVE-2012-1455: NOD32 and Rising Antivirus CAB parser malware detection bypass

Eset · Nod32 Antivirus

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into skipping malware detection when a CAB archive carries a modified vMinor version field. Because the scanner misreads the archive, malicious content inside the CAB can pass through without being flagged. The record notes this may later be split into separate CVEs if the flaw is confirmed to be independent in each parser.

4.3 CVSS 2.0 Medium EPSS 61% · top 0.9% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMinor version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than executing code directly, and the CVSS 2.0 score is 4.3, though the high EPSS and the security-control nature of the target raise concern.

What it is

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into skipping malware detection when a CAB archive carries a modified vMinor version field. Because the scanner misreads the archive, malicious content inside the CAB can pass through without being flagged. The record notes this may later be split into separate CVEs if the flaw is confirmed to be independent in each parser.

Impact

An attacker can deliver malware inside a crafted CAB file that the affected antivirus products fail to detect, leaving the host unprotected against the payload. The CVSS vector shows no confidentiality or availability impact, only a partial integrity impact.

Attack surface

Reached remotely over the network by supplying a crafted CAB file to the affected antivirus parser, with no authentication required. The vector indicates medium attack complexity and no user interaction requirement stated in the record.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high at 0.6113 (99.1st percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.

What to do

  • Apply the vendor fix for the affected NOD32 and Rising Antivirus versions; if no patch is available, upgrade to a current supported release.
  • Do not rely on the affected antivirus version as the sole control for CAB file inspection; add a second scanning layer or gateway that parses CAB archives independently.
  • Block or quarantine CAB attachments and downloads from untrusted sources at the mail and web gateway until the parser is fixed.
  • Track the NVD record for a possible CVE split, since the flaw may affect the two parsers separately and require separate fixes.

Detection

  • Hunt for CAB files with anomalous or unexpected vMinor version field values entering the environment through mail, web or removable media.
  • Monitor antivirus logs for CAB archives that are opened but produce no detection verdict, especially from external senders.
  • Correlate endpoint telemetry for processes spawned shortly after CAB extraction on hosts running the affected antivirus versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1455 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10180Eset cyber security interpretation conflict vulnerabilityThe ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart S…EPSS 1.7%9.3CVE-2008-5539Rising-global rising antivirus improper input validation vulnerabilityRISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware …EPSS 10%9.3CVE-2008-5534Eset nod32 antivirus improper input validation vulnerabilityESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML…EPSS 3.5%8.6CVE-2023-5594Eset endpoint antivirus improper certificate validation vulnerabilityImproper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …EPSS 0.38%7.8CVE-2024-0353Eset endpoint antivirus improper privilege management vulnerabilityLocal privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…EPSS 0.55%7.8CVE-2021-37851Eset endpoint antivirus vulnerabilityLocal privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run ma…EPSS 0.21%7.8CVE-2021-37852Eset endpoint antivirus improper privilege management vulnerabilityESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …EPSS 0.60%7.8CVE-2020-11446Eset antivirus and antispyware link following vulnerabilityESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2012-1455), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.