Vulnerability record · CVE-2012-1463 · published 21 March 2012
CVE-2012-1463: Multiple antivirus ELF parsers bypassed via modified endianness field
Ahnlab · V3 Internet Security
The ELF file parser in a dozen antivirus products (AhnLab V3, Bitdefender, Quick Heal, Command, Comodo, eSafe, F-Prot, F-Secure, McAfee, Norman, nProtect, Panda) fails to correctly handle a modified endianness field, allowing a crafted ELF file to evade malware detection. This matters because an attacker can deliver a malicious ELF binary that the scanner reports as clean, undermining the core protection these products provide.
Description
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 is 4.3 (MEDIUM) with no confidentiality or availability impact, but the flaw affects many widely deployed AV products and EPSS is very high.
What it is
The ELF file parser in a dozen antivirus products (AhnLab V3, Bitdefender, Quick Heal, Command, Comodo, eSafe, F-Prot, F-Secure, McAfee, Norman, nProtect, Panda) fails to correctly handle a modified endianness field, allowing a crafted ELF file to evade malware detection. This matters because an attacker can deliver a malicious ELF binary that the scanner reports as clean, undermining the core protection these products provide.
Impact
An attacker gains the ability to smuggle a malicious ELF file past the affected antivirus engines, enabling malware to reach and execute on a protected host without being flagged.
Attack surface
Reached remotely over the network by supplying a crafted ELF file to the scanning engine; no authentication is required, though some user interaction (e.g., opening or scanning the file) is implied by the AV:N/AC:M vector.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.94246, 99.8th percentile), suggesting elevated predicted exploitation activity.
What to do
- Apply vendor updates or hotfixes for the affected antivirus engines as soon as they are available.
- If no patch exists, disable or restrict scanning of untrusted ELF files, or route them through a second, unaffected scanner.
- Block or quarantine ELF files from untrusted sources at email and web gateways.
- Track vendor advisories for each listed product, since the note warns this CVE may be split into separate issues.
- Compensate with endpoint detection that does not rely solely on the affected AV parser.
Detection
- Monitor for ELF files with unusual or inconsistent endianness fields reaching AV scan queues.
- Alert on AV scan results that report clean for ELF files later found to be malicious.
- Correlate AV engine version against the affected product list and flag unpatched hosts.
- Hunt for ELF binaries delivered via email or web downloads that bypassed AV inspection.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1463 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1463), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.