← Vulnerability feed

Vulnerability record · CVE-2012-1462 · published 21 March 2012

CVE-2012-1462: ZIP parser in multiple antivirus products allows malware detection bypass

Ahnlab · V3 Internet Security

The ZIP file parser in numerous antivirus and endpoint protection products mishandles a ZIP archive containing an invalid data block at the beginning, allowing the parser to skip or misread content. Because the affected component is the malware scanner itself, a crafted archive can pass through scanning without being flagged. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 98% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe flaw defeats malware detection but requires a crafted archive and specific conditions, and no confirmed exploitation or KEV listing exists despite a very high EPSS score.

What it is

The ZIP file parser in numerous antivirus and endpoint protection products mishandles a ZIP archive containing an invalid data block at the beginning, allowing the parser to skip or misread content. Because the affected component is the malware scanner itself, a crafted archive can pass through scanning without being flagged. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

Impact

An attacker gains the ability to deliver malware inside a ZIP archive that the affected antivirus engine fails to detect, defeating the primary defense on the host. The CVSS 2.0 vector shows integrity impact only (I:P) with no confidentiality or availability impact.

Attack surface

Reached remotely over the network by supplying a crafted ZIP file to a system running one of the affected scanners; the vector AV:N/AC:M/Au:N indicates no authentication is required and some conditions must be met. User interaction is not stated in the record, but delivery of the archive to the scanning path is implied.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.97842, 99.9th percentile), but the reference tags are empty and no public exploit or in-the-wild confirmation is provided in this record.

What to do

  • Apply vendor updates for the affected antivirus and endpoint protection products; the record does not list fixed versions, so confirm patched builds with each vendor.
  • Do not rely on a single scanner for ZIP inspection; add a second engine or a dedicated archive inspection layer.
  • Block or quarantine inbound ZIP archives at the mail and web gateway until scanners are confirmed patched.
  • Where feasible, restrict or disable automatic scanning of untrusted archives by the affected engine and route them to sandbox analysis.
  • Track the note that this CVE may be split; monitor vendor advisories for per-product identifiers and fixes.

Detection

  • Monitor scanner logs for ZIP archives that are opened but return no verdict or an error, especially archives with malformed leading blocks.
  • Hunt for files that pass antivirus scanning but later execute or drop payloads, indicating a detection bypass.
  • Alert on ZIP files with invalid or truncated data at the start of the archive reaching endpoints or mail gateways.
  • Correlate endpoint execution of files extracted from ZIP archives against scanner verdicts to find gaps.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1462 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1784Avg anti-virus improper input validation vulnerabilityThe AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition,…EPSS 3.4%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%5.1CVE-2005-3231Cat quick heal vulnerabilityMultiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable …EPSS 14%5.0CVE-2005-3399Cat quick heal vulnerabilityMultiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…EPSS 7.8%

Source: NIST National Vulnerability Database (record CVE-2012-1462), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.