Executive Summary

Informations
NameCVE-2012-1434First vendor Publication2012-03-21
VendorCveLast vendor Modification2012-04-13

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score4.3Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityMedium
Cvss Expoit Score8.6AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1434

CWE : Common Weakness Enumeration

idName
CWE-264Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1
Application1
Application1
Application1

Snort® IPS/IDS

DateDescription
2014-01-10Portable Executable multiple antivirus evasion attempt
RuleID : 23311 - Revision : 5 - Type : FILE-EXECUTABLE

Internal Sources (Detail)

SourceUrl
BUGTRAQhttp://www.securityfocus.com/archive/1/522005
MISChttp://www.ieee-security.org/TC/SP2012/program.html

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2014-01-19 21:28:33
  • Multiple Updates
2013-05-10 22:35:43
  • Multiple Updates