← Vulnerability feed

Vulnerability record · CVE-2012-1458 · published 21 March 2012

CVE-2012-1458: ClamAV and Sophos CHM parser malware detection bypass

Clamav · Clamav

The CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 can be tricked into missing malware by a crafted reset interval in the LZXC header of a CHM file. Because these are the scanning engines themselves, a bypass means malicious content passes inspection undetected. The record notes it may later be split if the error proves independent across the two parser implementations.

4.3 CVSS 2.0 Medium EPSS 74% · top 0.5% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityIt is a detection bypass rather than direct code execution, but it undermines the antivirus control itself and carries a very high EPSS score.

What it is

The CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 can be tricked into missing malware by a crafted reset interval in the LZXC header of a CHM file. Because these are the scanning engines themselves, a bypass means malicious content passes inspection undetected. The record notes it may later be split if the error proves independent across the two parser implementations.

Impact

An attacker gains the ability to deliver a CHM file that evades detection by the affected antivirus engines, allowing malware to reach the endpoint without being flagged.

Attack surface

Reached remotely by supplying a crafted CHM file that the scanner parses; no authentication is required, though the CVSS vector indicates medium attack complexity. No user interaction is described beyond the file being scanned or opened.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is high at 0.73671 (99.4th percentile), indicating elevated predicted exploitation activity despite the absence of documented in-the-wild use.

What to do

  • Upgrade ClamAV and Sophos Anti-Virus to versions newer than 0.96.4 and 4.61.0 respectively, per vendor advisories.
  • Apply the referenced OpenSUSE, Mandriva and other distribution security updates for the packaged antivirus engines.
  • Add independent detection layers (YARA rules, sandboxing) for CHM files so a single parser bypass does not equal full evasion.
  • Restrict or block untrusted CHM file delivery at mail and web gateways where operationally feasible.

Detection

  • Monitor for CHM files with anomalous or unusual LZXC header reset interval values reaching endpoints or mail gateways.
  • Alert on antivirus engine version inventory showing ClamAV 0.96.4 or Sophos 4.61.0 still in production.
  • Correlate endpoint execution of CHM content with absence of corresponding AV detection events as a possible bypass indicator.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1458 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0098Clamav vulnerabilityClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafte…EPSS 4.9%10.0CVE-2009-1372Clamav memory buffer overflow vulnerabilityStack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial…EPSS 7.6%10.0CVE-2008-3914Clamav information exposure vulnerabilityMultiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path…EPSS 3.6%10.0CVE-2008-0728Clamav vulnerabilityThe unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."EPSS 2.8%10.0CVE-2006-6335Sophos anti-virus vulnerabilityMultiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive wit…EPSS 13%10.0CVE-2006-1615Clamav vulnerabilityMultiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary…EPSS 12%9.8CVE-2025-20260Clamav heap-based buffer overflow vulnerabilityA vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a…EPSS 1.6%9.8CVE-2023-20032Cisco secure endpoint classic buffer overflow vulnerabilityOn Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamA…EPSS 29%

Source: NIST National Vulnerability Database (record CVE-2012-1458), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.