Vulnerability record · CVE-2012-1455 · published 21 March 2012
CVE-2012-1455: NOD32 and Rising Antivirus CAB parser malware detection bypass
Eset · Nod32 Antivirus
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into skipping malware detection when a CAB archive carries a modified vMinor version field. Because the scanner misreads the archive, malicious content inside the CAB can pass through without being flagged. The record notes this may later be split into separate CVEs if the flaw is confirmed to be independent in each parser.
Description
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMinor version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than executing code directly, and the CVSS 2.0 score is 4.3, though the high EPSS and the security-control nature of the target raise concern.
What it is
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 can be tricked into skipping malware detection when a CAB archive carries a modified vMinor version field. Because the scanner misreads the archive, malicious content inside the CAB can pass through without being flagged. The record notes this may later be split into separate CVEs if the flaw is confirmed to be independent in each parser.
Impact
An attacker can deliver malware inside a crafted CAB file that the affected antivirus products fail to detect, leaving the host unprotected against the payload. The CVSS vector shows no confidentiality or availability impact, only a partial integrity impact.
Attack surface
Reached remotely over the network by supplying a crafted CAB file to the affected antivirus parser, with no authentication required. The vector indicates medium attack complexity and no user interaction requirement stated in the record.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high at 0.6113 (99.1st percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.
What to do
- Apply the vendor fix for the affected NOD32 and Rising Antivirus versions; if no patch is available, upgrade to a current supported release.
- Do not rely on the affected antivirus version as the sole control for CAB file inspection; add a second scanning layer or gateway that parses CAB archives independently.
- Block or quarantine CAB attachments and downloads from untrusted sources at the mail and web gateway until the parser is fixed.
- Track the NVD record for a possible CVE split, since the flaw may affect the two parsers separately and require separate fixes.
Detection
- Hunt for CAB files with anomalous or unexpected vMinor version field values entering the environment through mail, web or removable media.
- Monitor antivirus logs for CAB archives that are opened but produce no detection verdict, especially from external senders.
- Correlate endpoint telemetry for processes spawned shortly after CAB extraction on hosts running the affected antivirus versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1455 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1455), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.