← Vulnerability feed

Vulnerability record · CVE-2012-1463 · published 21 March 2012

CVE-2012-1463: Multiple antivirus ELF parsers bypassed via modified endianness field

Ahnlab · V3 Internet Security

The ELF file parser in a dozen antivirus products (AhnLab V3, Bitdefender, Quick Heal, Command, Comodo, eSafe, F-Prot, F-Secure, McAfee, Norman, nProtect, Panda) fails to correctly handle a modified endianness field, allowing a crafted ELF file to evade malware detection. This matters because an attacker can deliver a malicious ELF binary that the scanner reports as clean, undermining the core protection these products provide.

4.3 CVSS 2.0 Medium EPSS 94% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 is 4.3 (MEDIUM) with no confidentiality or availability impact, but the flaw affects many widely deployed AV products and EPSS is very high.

What it is

The ELF file parser in a dozen antivirus products (AhnLab V3, Bitdefender, Quick Heal, Command, Comodo, eSafe, F-Prot, F-Secure, McAfee, Norman, nProtect, Panda) fails to correctly handle a modified endianness field, allowing a crafted ELF file to evade malware detection. This matters because an attacker can deliver a malicious ELF binary that the scanner reports as clean, undermining the core protection these products provide.

Impact

An attacker gains the ability to smuggle a malicious ELF file past the affected antivirus engines, enabling malware to reach and execute on a protected host without being flagged.

Attack surface

Reached remotely over the network by supplying a crafted ELF file to the scanning engine; no authentication is required, though some user interaction (e.g., opening or scanning the file) is implied by the AV:N/AC:M vector.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.94246, 99.8th percentile), suggesting elevated predicted exploitation activity.

What to do

  • Apply vendor updates or hotfixes for the affected antivirus engines as soon as they are available.
  • If no patch exists, disable or restrict scanning of untrusted ELF files, or route them through a second, unaffected scanner.
  • Block or quarantine ELF files from untrusted sources at email and web gateways.
  • Track vendor advisories for each listed product, since the note warns this CVE may be split into separate issues.
  • Compensate with endpoint detection that does not rely solely on the affected AV parser.

Detection

  • Monitor for ELF files with unusual or inconsistent endianness fields reaching AV scan queues.
  • Alert on AV scan results that report clean for ELF files later found to be malicious.
  • Correlate AV engine version against the affected product list and flag unpatched hosts.
  • Hunt for ELF binaries delivered via email or web downloads that bypassed AV inspection.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1463 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2008-5409Bitdefender antivirus memory buffer overflow vulnerabilityUnspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, an…EPSS 11%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%5.1CVE-2005-3231Cat quick heal vulnerabilityMultiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable …EPSS 14%5.0CVE-2005-3399Cat quick heal vulnerabilityMultiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…EPSS 7.8%

Source: NIST National Vulnerability Database (record CVE-2012-1463), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.