CVE-2012-1453

Antiy Avl SDK - Access Control

Title source: rule
STIX 2.1

Description

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80487
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80484
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80482
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80489
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80488
Various Sources x_refsource_misc
http://www.ieee-security.org/TC/SP2012/program.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80486
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80483
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80485
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/522005
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52621

Scores

EPSS 0.7848
EPSS Percentile 99.1%

Details

CWE
CWE-264
Status published
Products (14)
antiy/avl_sdk 2.0.3.7
ca/etrust_vet_antivirus 36.1.8511
drweb/dr.web_antivirus 5.0.2.03300
emsisoft/anti-malware 5.1.0.1
fortinet/fortinet_antivirus 4.2.254.0
ikarus/ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
kaspersky/kaspersky_anti-virus 7.0.0.125
mcafee/gateway 2010.1c
microsoft/security_essentials 2.0
pandasecurity/panda_antivirus 10.0.2.7
... and 4 more
Published Mar 21, 2012
Tracked Since Feb 18, 2026