MEDIUM · 4.3

CVE-2012-1433

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus ...

Vulnerability Description

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AhnlabV3 Internet Security2011.01.18.00
AladdinEsafe7.0.17.0
EmsisoftAnti-Malware5.1.0.1
IkarusIkarus Virus Utilities T3 Command Line Scanner1.1.97.0
PandasecurityPanda Antivirus10.0.2.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1433?

CVE-2012-1433 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus ...

How severe is CVE-2012-1433?

CVE-2012-1433 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1433?

Check the references section above for vendor advisories and patch information. Affected products include: Ahnlab V3 Internet Security, Aladdin Esafe, Emsisoft Anti-Malware, Ikarus Ikarus Virus Utilities T3 Command Line Scanner, Pandasecurity Panda Antivirus.