CVE-2012-1453

N/A Unknown
Published: March 21, 2012 Modified: April 29, 2026
View on NVD

Description

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/80482
Source: cve@mitre.org
http://osvdb.org/80483
Source: cve@mitre.org
http://osvdb.org/80484
Source: cve@mitre.org
http://osvdb.org/80485
Source: cve@mitre.org
http://osvdb.org/80486
Source: cve@mitre.org
http://osvdb.org/80487
Source: cve@mitre.org
http://osvdb.org/80488
Source: cve@mitre.org
http://osvdb.org/80489
Source: cve@mitre.org
http://osvdb.org/80482
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80483
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80484
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80485
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80486
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80487
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80488
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80489
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ieee-security.org/TC/SP2012/program.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/522005
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/52621
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
97.7%
100th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

microsoft drweb ikarus ca fortinet mcafee pandasecurity antiy sophos rising-global +3 more