CVE-2009-1240

Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of malware via a modified RAR archive.

Published: 2009-04-03 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-1240 is rated High Risk (66.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.92%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-1240

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-08-23 1.03% 0.92% -0.11%
2 2025-03-30 2.20% 1.03% -1.17%
3 2025-03-29 2.20%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-1240

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2009-1240

NVD evaluator notes for CVE-2009-1240

Comment: Per: http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=5417 Although the Virus Prevention System technology was, at one time, incorporated into the IBM Proventia Network MFS and the Proventia Network Mail appliances, this capability was removed in Jan 2008. For this reason, this vulnerability does not apply to these product lines. The Virus Prevention System technology is currently incorporated into Proventia Desktop. However, the Proventia Desktop product is not affected by this evasion. No other IBM ISS products currently incorporate the Virus Prevention System technology.

Affected software / configurations for CVE-2009-1240

Vendor Product Version Raw CPE
ibm proventia_desktop_endpoint_security cpe:2.3:a:ibm:proventia_desktop_endpoint_security:*:*:*:*:*:*:*:*
ibm proventia_network_mail_security_system cpe:2.3:a:ibm:proventia_network_mail_security_system:*:*:*:*:*:*:*:*
ibm network_multi-function_security cpe:2.3:h:ibm:network_multi-function_security:*:*:*:*:*:*:*:*
ibm proventia_network_mail_security_system_virtual_appliance cpe:2.3:h:ibm:proventia_network_mail_security_system_virtual_appliance:*:*:*:*:*:*:*:*

References for CVE-2009-1240

cvelogic Threat Intelligence