peter bassill · operator
$ cve CVE-2004-0932 JSON

CVE-2004-0932 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 63.4% (pctl 99)

Patch early

A public exploit exists.

Description

McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS63.39% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2005-01-27
Last modified2026-06-16

Affected (23)

VendorProduct
archive ziparchive zip
broadcombrightstor arcserve backup
broadcometrust antivirus
broadcometrust antivirus gateway
broadcometrust ez antivirus
broadcometrust ez armor
broadcometrust intrusion detection
broadcometrust secure content manager
broadcominoculateit
caetrust antivirus
caetrust secure content manager
eset softwarenod32 antivirus
gentoolinux
kaspersky labkaspersky anti-virus
mandrakesoftmandrake linux
mcafeeantivirus engine
rav antivirusrav antivirus desktop
rav antivirusrav antivirus for file servers
rav antivirusrav antivirus for mail servers
sophossophos anti-virus
sophossophos puremessage anti-virus
sophossophos small business suite
susesuse linux

Public exploits

SourceTitleDate
exploit-dbMultiple AntiVirus - '.zip' Detection Bypass2004-11-14

References

→ the Explorer  ·  watch your stack  ·  NVD