Vulnerability record · CVE-2012-1421 · published 21 March 2012
CVE-2012-1421: Antivirus TAR parser malware detection bypass via MSCF sequence
Cat · Quick Heal
The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and the AVEngine component of Symantec Endpoint Protection 11 can be tricked into bypassing malware detection by a POSIX TAR file that begins with an MSCF character sequence. Because the parser misreads the archive, malicious content inside is not flagged, undermining the core protective function of these antivirus products. The record notes it may later be split into separate CVEs if the flaw proves independent across the different TAR parser implementations.
Description
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than granting code execution, but it weakens a primary security control and carries a very high EPSS score.
What it is
The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and the AVEngine component of Symantec Endpoint Protection 11 can be tricked into bypassing malware detection by a POSIX TAR file that begins with an MSCF character sequence. Because the parser misreads the archive, malicious content inside is not flagged, undermining the core protective function of these antivirus products. The record notes it may later be split into separate CVEs if the flaw proves independent across the different TAR parser implementations.
Impact
An attacker can deliver malware that the affected antivirus engines fail to detect, allowing it to reach the endpoint and execute without being quarantined. The attacker gains no direct code execution from the flaw itself; the gain is evasion of the security control.
Attack surface
Reached remotely over the network by supplying a crafted TAR file to the scanning engine, for example as an email attachment or downloaded file. No authentication is required, but the CVSS vector indicates medium attack complexity and some condition must be met for the bypass to succeed.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, though EPSS is very high (0.89182, 99.8th percentile), suggesting elevated predicted likelihood of exploitation activity.
What to do
- Apply vendor updates for the affected antivirus and endpoint protection products; this is a 2012 issue, so confirm current supported versions are in use.
- Where no fix exists for an affected legacy product, migrate to a supported antivirus or endpoint protection platform.
- Block or quarantine TAR archives at the email and web gateway until engines are confirmed patched.
- Do not rely solely on signature-based scanning for TAR content; enable behavioral and reputation-based detection layers.
- Verify detection by testing a benign POSIX TAR file with an MSCF prefix against the deployed engine.
Detection
- Monitor for TAR files whose contents begin with the MSCF byte sequence and alert on their delivery or extraction.
- Correlate endpoint telemetry for processes spawned from archive extraction paths that antivirus did not flag.
- Review antivirus scan logs for TAR archives reported as clean where downstream behavior indicates malicious activity.
- Hunt for repeated delivery of archive attachments from the same sender or host that evade scanning.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1421 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1421), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.