CVE-2012-1463: Ahnlab v3 Internet Security
Medium severity, CVSS 4.3. EPSS: 94.2% chance of exploitation in the next 30 days.
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
Affected products
- Ahnlab v3 Internet Security: version 2011.01.18.00 only
- Aladdin Esafe: version 7.0.17.0 only
- Authentium Command Antivirus: version 5.2.11.5 only
- Bitdefender Bitdefender: version 7.2 only
- Cat Quick Heal: version 11.00 only
- Comodo Comodo Antivirus: version 7424 only
- F-Prot F-Prot Antivirus: version 4.6.2.117 only
- F-Secure F-Secure Anti-Virus: version 9.0.16160.0 only
- McAfee Scan Engine: version 5.400.0.1158 only
- Norman Norman Antivirus & Antispyware: version 6.06.12 only
- Nprotect Nprotect Antivirus: version 2011-01-17.01 only
- Pandasecurity Panda Antivirus: version 10.0.2.7 only
Published 2012-03-21. Last modified 2026-06-16.