← Vulnerability feed

Vulnerability record · CVE-2012-1421 · published 21 March 2012

CVE-2012-1421: Antivirus TAR parser malware detection bypass via MSCF sequence

Cat · Quick Heal

The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and the AVEngine component of Symantec Endpoint Protection 11 can be tricked into bypassing malware detection by a POSIX TAR file that begins with an MSCF character sequence. Because the parser misreads the archive, malicious content inside is not flagged, undermining the core protective function of these antivirus products. The record notes it may later be split into separate CVEs if the flaw proves independent across the different TAR parser implementations.

4.3 CVSS 2.0 Medium EPSS 89% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than granting code execution, but it weakens a primary security control and carries a very high EPSS score.

What it is

The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and the AVEngine component of Symantec Endpoint Protection 11 can be tricked into bypassing malware detection by a POSIX TAR file that begins with an MSCF character sequence. Because the parser misreads the archive, malicious content inside is not flagged, undermining the core protective function of these antivirus products. The record notes it may later be split into separate CVEs if the flaw proves independent across the different TAR parser implementations.

Impact

An attacker can deliver malware that the affected antivirus engines fail to detect, allowing it to reach the endpoint and execute without being quarantined. The attacker gains no direct code execution from the flaw itself; the gain is evasion of the security control.

Attack surface

Reached remotely over the network by supplying a crafted TAR file to the scanning engine, for example as an email attachment or downloaded file. No authentication is required, but the CVSS vector indicates medium attack complexity and some condition must be met for the bypass to succeed.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, though EPSS is very high (0.89182, 99.8th percentile), suggesting elevated predicted likelihood of exploitation activity.

What to do

  • Apply vendor updates for the affected antivirus and endpoint protection products; this is a 2012 issue, so confirm current supported versions are in use.
  • Where no fix exists for an affected legacy product, migrate to a supported antivirus or endpoint protection platform.
  • Block or quarantine TAR archives at the email and web gateway until engines are confirmed patched.
  • Do not rely solely on signature-based scanning for TAR content; enable behavioral and reputation-based detection layers.
  • Verify detection by testing a benign POSIX TAR file with an MSCF prefix against the deployed engine.

Detection

  • Monitor for TAR files whose contents begin with the MSCF byte sequence and alert on their delivery or extraction.
  • Correlate endpoint telemetry for processes spawned from archive extraction paths that antivirus did not flag.
  • Review antivirus scan logs for TAR archives reported as clean where downstream behavior indicates malicious activity.
  • Hunt for repeated delivery of archive attachments from the same sender or host that evade scanning.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1421 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0108Symantec antivirus memory buffer overflow vulnerabilityBuffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9…EPSS 19%10.0CVE-2009-1429Symantec AMS2 Intel LANDesk CBA Remote Command ExecutionThe Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA …EPSS 88%analysed9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%9.3CVE-2012-4953Symantec antivirus memory buffer overflow vulnerabilityThe decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corpor…EPSS 6.0%9.3CVE-2012-0295Symantec endpoint protection code injection vulnerabilityThe Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…EPSS 4.0%9.3CVE-2009-1430Symantec Alert Management System IAO.EXE stack buffer overflowIAO.EXE in the Symantec Alert Originator Service (Alert Management System 2, shipped with System Center, AntiVirus, Client Security and Endpoint Prot…EPSS 55%analysed9.3CVE-2009-1431Symantec antivirus vulnerabilityXFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Syma…EPSS 8.0%9.3CVE-2008-5539Rising-global rising antivirus improper input validation vulnerabilityRISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware …EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2012-1421), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.