← Vulnerability feed

Vulnerability record · CVE-2012-1420 · published 21 March 2012

CVE-2012-1420: Antivirus TAR parser malware detection bypass via crafted POSIX TAR file

Authentium · Command Antivirus

Multiple antivirus products' TAR file parsers fail to correctly handle a POSIX TAR file whose content begins with a \7fELF character sequence, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus layer undetected. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 97% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe flaw undermines malware detection across many widely deployed antivirus products, but CVSS is only 4.3 and there is no confirmed in-the-wild exploitation or KEV listing.

What it is

Multiple antivirus products' TAR file parsers fail to correctly handle a POSIX TAR file whose content begins with a \7fELF character sequence, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus layer undetected. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

Impact

An attacker can deliver malware inside a crafted TAR archive that the affected antivirus engine fails to flag, defeating the primary detection control on the host or gateway. The CVSS vector shows integrity impact only, with no confidentiality or availability loss.

Attack surface

Reached remotely over the network (AV:N) by supplying a crafted TAR file to the scanning engine; no authentication is required (Au:N), though the vector indicates medium attack complexity (AC:M). No user interaction is specified in the record.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.97111, 99.889th percentile), suggesting elevated predicted exploitation activity.

What to do

  • Apply vendor updates for the affected antivirus and antimalware engines; the record does not list fixed versions, so confirm remediation status with each vendor.
  • Where no fix exists, supplement TAR scanning with a second, independently implemented detection engine or sandbox detonation.
  • Block or quarantine TAR archives from untrusted sources at mail and web gateways until engines are confirmed patched.
  • Verify detection by testing a benign POSIX TAR file beginning with the \7fELF sequence against current engine versions.
  • Track vendor advisories for the possible CVE split, since fixes may be issued per parser implementation.

Detection

  • Monitor for TAR archives containing files whose first bytes are \x7fELF, which is anomalous for archive contents.
  • Alert on endpoint or gateway logs where TAR files pass scanning without a verdict or with parser errors.
  • Correlate antivirus engine version inventory against vendor advisories to find unpatched scanners.
  • Review mail and proxy logs for repeated TAR attachments from the same sender or host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1420 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1783F-prot antivirus improper input validation vulnerabilityMultiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Se…EPSS 3.4%9.8CVE-2020-10180Eset cyber security interpretation conflict vulnerabilityThe ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart S…EPSS 1.7%9.3CVE-2008-5534Eset nod32 antivirus improper input validation vulnerabilityESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML…EPSS 3.5%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%8.6CVE-2023-5594Eset endpoint antivirus improper certificate validation vulnerabilityImproper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …EPSS 0.38%7.8CVE-2024-0353Eset endpoint antivirus improper privilege management vulnerabilityLocal privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…EPSS 0.55%7.8CVE-2021-37851Eset endpoint antivirus vulnerabilityLocal privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run ma…EPSS 0.21%7.8CVE-2021-37852Eset endpoint antivirus improper privilege management vulnerabilityESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2012-1420), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.