CVE-2012-1442

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, Antiy Labs AVL SDK 2.0.3.7, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified class field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

公開: 2012-03-21 最後更新: 2026-06-16 指派方: [email protected] 來源: [email protected]

結論預警: CVE-2012-1442 綜合評估為中等風險(57.2/100):CVSS 技術影響為中級,利用機率偏高(EPSS 98.95%,百分位 100%) 核心證據: EPSS 顯示該漏洞近期被利用的可能性處於高位。 近一日 EPSS 上升 +96.11%,被利用關注度持續升高。 強制指令: 被利用機率偏高—請盤點暴露面並優先安排修補。

風險隨態勢動態變化;本站持續評估並同步更新本頁展示內容。

CVE-2012-1442 的 EPSS(利用預測評分)

EPSS 日更估計相對被利用可能性;百分位表示該 CVE 在已評分漏洞中的相對排名(越高表示相對更嚴重)。

# 日期 舊 EPSS 分數 新 EPSS 分數 變化(新 − 舊)
1 2026-06-15 2.84% 98.95% +96.11%
2 2025-06-03 3.81% 2.84% -0.97%
3 2025-03-30 3.81%

完整 EPSS 歷史 (共 8 筆)

CVE-2012-1442 的 CVSS 指標

該 CVE 的 CVSS 指標。

底座分 版本 嚴重度 向量 可利用性 影響 分數來源
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N 點擊展開
存取路徑 (AV:N)
只要路由可達,即可從遠端發動利用。
存取複雜度 (AC:M)
需要若干有利條件,但不必「千年一遇」。
認證 (AU:N)
全程無需有效身分。
機密性影響 (C:N)
對機密性無影響。
完整性影響 (I:P)
完整性受到部分損害。
可用性影響 (A:N)
對可用性無影響。
8.6 2.9 [email protected]

CVE-2012-1442 的弱點列舉

CVE-2012-1442 的影響軟體 / 設定

廠商 產品 版本 原始 CPE
aladdin esafe 7.0.17.0 cpe:2.3:a:aladdin:esafe:7.0.17.0:*:*:*:*:*:*:*
antiy avl_sdk 2.0.3.7 cpe:2.3:a:antiy:avl_sdk:2.0.3.7:*:*:*:*:*:*:*
cat quick_heal 11.00 cpe:2.3:a:cat:quick_heal:11.00:*:*:*:*:*:*:*
f-secure f-secure_anti-virus 9.0.16160.0 cpe:2.3:a:f-secure:f-secure_anti-virus:9.0.16160.0:*:*:*:*:*:*:*
fortinet fortinet_antivirus 4.2.254.0 cpe:2.3:a:fortinet:fortinet_antivirus:4.2.254.0:*:*:*:*:*:*:*
kaspersky kaspersky_anti-virus 7.0.0.125 cpe:2.3:a:kaspersky:kaspersky_anti-virus:7.0.0.125:*:*:*:*:*:*:*
mcafee gateway 2010.1c cpe:2.3:a:mcafee:gateway:2010.1c:*:*:*:*:*:*:*
mcafee scan_engine 5.400.0.1158 cpe:2.3:a:mcafee:scan_engine:5.400.0.1158:*:*:*:*:*:*:*
pandasecurity panda_antivirus 10.0.2.7 cpe:2.3:a:pandasecurity:panda_antivirus:10.0.2.7:*:*:*:*:*:*:*
rising-global rising_antivirus 22.83.00.03 cpe:2.3:a:rising-global:rising_antivirus:22.83.00.03:*:*:*:*:*:*:*
sophos sophos_anti-virus 4.61.0 cpe:2.3:a:sophos:sophos_anti-virus:4.61.0:*:*:*:*:*:*:*

CVE-2012-1442 的參考連結

cvelogic Threat Intelligence