Vulnerability record · CVE-2012-1458 · published 21 March 2012
CVE-2012-1458: ClamAV and Sophos CHM parser malware detection bypass
Clamav · Clamav
The CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 can be tricked into missing malware by a crafted reset interval in the LZXC header of a CHM file. Because these are the scanning engines themselves, a bypass means malicious content passes inspection undetected. The record notes it may later be split if the error proves independent across the two parser implementations.
Description
The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityIt is a detection bypass rather than direct code execution, but it undermines the antivirus control itself and carries a very high EPSS score.
What it is
The CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 can be tricked into missing malware by a crafted reset interval in the LZXC header of a CHM file. Because these are the scanning engines themselves, a bypass means malicious content passes inspection undetected. The record notes it may later be split if the error proves independent across the two parser implementations.
Impact
An attacker gains the ability to deliver a CHM file that evades detection by the affected antivirus engines, allowing malware to reach the endpoint without being flagged.
Attack surface
Reached remotely by supplying a crafted CHM file that the scanner parses; no authentication is required, though the CVSS vector indicates medium attack complexity. No user interaction is described beyond the file being scanned or opened.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is high at 0.73671 (99.4th percentile), indicating elevated predicted exploitation activity despite the absence of documented in-the-wild use.
What to do
- Upgrade ClamAV and Sophos Anti-Virus to versions newer than 0.96.4 and 4.61.0 respectively, per vendor advisories.
- Apply the referenced OpenSUSE, Mandriva and other distribution security updates for the packaged antivirus engines.
- Add independent detection layers (YARA rules, sandboxing) for CHM files so a single parser bypass does not equal full evasion.
- Restrict or block untrusted CHM file delivery at mail and web gateways where operationally feasible.
Detection
- Monitor for CHM files with anomalous or unusual LZXC header reset interval values reaching endpoints or mail gateways.
- Alert on antivirus engine version inventory showing ClamAV 0.96.4 or Sophos 4.61.0 still in production.
- Correlate endpoint execution of CHM content with absence of corresponding AV detection events as a possible bypass indicator.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1458 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1458), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.