Vulnerability record · CVE-2012-1422 · published 21 March 2012
CVE-2012-1422: Antivirus TAR parser malware detection bypass via ITSF sequence
Cat · Quick Heal
The TAR file parser in Quick Heal 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 fails to correctly handle a POSIX TAR file beginning with an ITSF character sequence, allowing malware to evade detection. This matters because a scanner that misses a malicious archive gives false assurance while the payload reaches the endpoint. The record notes the issue may later be split into separate CVEs if the error proves independent across the different TAR parser implementations.
Description
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial ITSF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityIt is a detection bypass with no confirmed exploitation and only medium CVSS impact, but it affects widely deployed antivirus engines and carries a very high EPSS score.
What it is
The TAR file parser in Quick Heal 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 fails to correctly handle a POSIX TAR file beginning with an ITSF character sequence, allowing malware to evade detection. This matters because a scanner that misses a malicious archive gives false assurance while the payload reaches the endpoint. The record notes the issue may later be split into separate CVEs if the error proves independent across the different TAR parser implementations.
Impact
An attacker can deliver a malicious TAR archive that the affected antivirus products do not flag, so malware reaches the target host without the scanner raising an alert. The flaw is a detection bypass, not code execution in the scanner itself.
Attack surface
Reached remotely over the network by supplying a crafted POSIX TAR file to a system whose antivirus scans it; no authentication is required per the AV:N/Au:N vector. Some user or automated action to bring the file into the scan path is implied by AC:M, but the record does not specify the exact delivery mechanism.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is very high (0.94059, 99.8th percentile), indicating strong predicted likelihood of exploitation activity, though that score should be treated cautiously for a 2012 detection-bypass issue.
What to do
- Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm current patched builds with each vendor.
- Do not rely on the affected scanner versions as the sole malware control; layer endpoint detection and email/web gateway scanning from other engines.
- Block or quarantine TAR archives at the perimeter and inspect them with a parser that handles the ITSF prefix correctly.
- Retire or upgrade end-of-life products such as Quick Heal 11.00, NOD32 5795, Norman 6.06.12, and Rising 22.83.00.03, which are long unsupported.
- Alert on TAR files whose leading bytes are the ITSF sequence and treat them as suspicious.
Detection
- Search file-scan and gateway logs for TAR archives beginning with the ITSF byte sequence.
- Correlate antivirus scan results with subsequent process execution from extracted archive contents to catch missed payloads.
- Monitor for the affected product versions in asset inventory and flag hosts still running them.
- Review email and web download logs for TAR attachments or downloads that passed scanning without a verdict.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1422 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1422), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.