CVE-2004-0935 describes a bypass vulnerability in Eset Anti-Virus versions prior to 1.020, and other antivirus products, where specially crafted compressed files with zeroed local and global headers could evade detection. This allows remote attackers to bypass antivirus protection, potentially leading to the execution of malicious code. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P), it is considered highly severe, indicating easy exploitation over a network with potential for partial compromise of confidentiality, integrity, and availability. While not actively exploited in the wild (no KEV entry), exploit code exists on ExploitDB, and it has garnered significant community discussion, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.13CPE matchmatch criteria | cpe:2.3:a:archive_zip:archive_zip:1.13:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:broadcom:etrust_antivirus:7.0:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:broadcom:etrust_antivirus:7.1:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:broadcom:etrust_antivirus_gateway:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.