mediumREV. 01

CVE-2012-1459Antivirus Engines — Archive Parsing Differential, Second Set

A second group of antivirus engines reads a crafted archive differently from the tools that later unpack it, which lets an attacker hide a malicious file where the scanner does not look.

YOUR NEXT MOVE

Update the scanning engines, and unpack archives with the same library the scanner used.

Read the risk

THE VITAL STATS
CVSS score
—/ 10
No score recorded
EPSS probability
100%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Not listed
CVE published
2012-03-21
Exploit published
Not recorded
Confidence
medium
Kill chain
defense evasion
MITRE ATT&CK
T1027
Severity
medium

Attacker needsAn archive the target will scan and then extract

Behind the card

1 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-08-07scrty-crds-pipeline/0.1high
epssapi.first.org2026-08-07scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2012-1459 · CRDS 0.1 · Issued 2026-08-07