CVE-2012-1453: Antiy Avl SDK

Medium severity, CVSS 4.3. EPSS: 97.7% chance of exploitation in the next 30 days.

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

Affected products

  • Antiy Avl SDK: version 2.0.3.7 only
  • Ca Etrust Vet Antivirus: version 36.1.8511 only
  • Drweb Dr.web Antivirus: version 5.0.2.03300 only
  • Emsisoft Anti-Malware: version 5.1.0.1 only
  • Fortinet Fortinet Antivirus: version 4.2.254.0 only
  • Ikarus Ikarus Virus Utilities t3 Command Line Scanner: version 1.1.97.0 only
  • Kaspersky Kaspersky Anti-Virus: version 7.0.0.125 only
  • McAfee Gateway: version 2010.1c only
  • Microsoft Security Essentials: version 2.0 only
  • Pandasecurity Panda Antivirus: version 10.0.2.7 only
  • Rising-Global Rising Antivirus: version 22.83.00.03 only
  • Sophos Sophos Anti-Virus: version 4.61.0 only
  • Trend Micro Housecall: version 9.120.0.1004 only
  • Trend Micro Trend Micro Antivirus: version 9.120.0.1004 only

Published 2012-03-21. Last modified 2026-06-16.