Vulnerability record · CVE-2012-1420 · published 21 March 2012
CVE-2012-1420: Antivirus TAR parser malware detection bypass via crafted POSIX TAR file
Authentium · Command Antivirus
Multiple antivirus products' TAR file parsers fail to correctly handle a POSIX TAR file whose content begins with a \7fELF character sequence, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus layer undetected. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Description
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw undermines malware detection across many widely deployed antivirus products, but CVSS is only 4.3 and there is no confirmed in-the-wild exploitation or KEV listing.
What it is
Multiple antivirus products' TAR file parsers fail to correctly handle a POSIX TAR file whose content begins with a \7fELF character sequence, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus layer undetected. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Impact
An attacker can deliver malware inside a crafted TAR archive that the affected antivirus engine fails to flag, defeating the primary detection control on the host or gateway. The CVSS vector shows integrity impact only, with no confidentiality or availability loss.
Attack surface
Reached remotely over the network (AV:N) by supplying a crafted TAR file to the scanning engine; no authentication is required (Au:N), though the vector indicates medium attack complexity (AC:M). No user interaction is specified in the record.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.97111, 99.889th percentile), suggesting elevated predicted exploitation activity.
What to do
- Apply vendor updates for the affected antivirus and antimalware engines; the record does not list fixed versions, so confirm remediation status with each vendor.
- Where no fix exists, supplement TAR scanning with a second, independently implemented detection engine or sandbox detonation.
- Block or quarantine TAR archives from untrusted sources at mail and web gateways until engines are confirmed patched.
- Verify detection by testing a benign POSIX TAR file beginning with the \7fELF sequence against current engine versions.
- Track vendor advisories for the possible CVE split, since fixes may be issued per parser implementation.
Detection
- Monitor for TAR archives containing files whose first bytes are \x7fELF, which is anomalous for archive contents.
- Alert on endpoint or gateway logs where TAR files pass scanning without a verdict or with parser errors.
- Correlate antivirus engine version inventory against vendor advisories to find unpatched scanners.
- Review mail and proxy logs for repeated TAR attachments from the same sender or host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1420 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1420), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.