CVE-2012-1446

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

Published: 2012-03-21 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-1446 is rated Moderate Risk (46/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.54%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2012-1446

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-06-03 3.40% 2.54% -0.87%
2 2025-03-30 3.75% 3.40% -0.34%
3 2025-03-29 3.75%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-1446

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2012-1446

Affected software / configurations for CVE-2012-1446

Vendor Product Version Raw CPE
aladdin esafe 7.0.17.0 cpe:2.3:a:aladdin:esafe:7.0.17.0:*:*:*:*:*:*:*
antiy avl_sdk 2.0.3.7 cpe:2.3:a:antiy:avl_sdk:2.0.3.7:*:*:*:*:*:*:*
ca etrust_vet_antivirus 36.1.8511 cpe:2.3:a:ca:etrust_vet_antivirus:36.1.8511:*:*:*:*:*:*:*
cat quick_heal 11.00 cpe:2.3:a:cat:quick_heal:11.00:*:*:*:*:*:*:*
fortinet fortinet_antivirus 4.2.254.0 cpe:2.3:a:fortinet:fortinet_antivirus:4.2.254.0:*:*:*:*:*:*:*
kaspersky kaspersky_anti-virus 7.0.0.125 cpe:2.3:a:kaspersky:kaspersky_anti-virus:7.0.0.125:*:*:*:*:*:*:*
mcafee gateway 2010.1c cpe:2.3:a:mcafee:gateway:2010.1c:*:*:*:*:*:*:*
mcafee scan_engine 5.400.0.1158 cpe:2.3:a:mcafee:scan_engine:5.400.0.1158:*:*:*:*:*:*:*
norman norman_antivirus_\&_antispyware 6.06.12 cpe:2.3:a:norman:norman_antivirus_\&_antispyware:6.06.12:*:*:*:*:*:*:*
pandasecurity panda_antivirus 10.0.2.7 cpe:2.3:a:pandasecurity:panda_antivirus:10.0.2.7:*:*:*:*:*:*:*
pc_tools pc_tools_antivirus 7.0.3.5 cpe:2.3:a:pc_tools:pc_tools_antivirus:7.0.3.5:*:*:*:*:*:*:*
rising-global rising_antivirus 22.83.00.03 cpe:2.3:a:rising-global:rising_antivirus:22.83.00.03:*:*:*:*:*:*:*
sophos sophos_anti-virus 4.61.0 cpe:2.3:a:sophos:sophos_anti-virus:4.61.0:*:*:*:*:*:*:*
symantec endpoint_protection 11.0 cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*

References for CVE-2012-1446

cvelogic Threat Intelligence