← Vulnerability feed

Vulnerability record · CVE-2012-1422 · published 21 March 2012

CVE-2012-1422: Antivirus TAR parser malware detection bypass via ITSF sequence

Cat · Quick Heal

The TAR file parser in Quick Heal 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 fails to correctly handle a POSIX TAR file beginning with an ITSF character sequence, allowing malware to evade detection. This matters because a scanner that misses a malicious archive gives false assurance while the payload reaches the endpoint. The record notes the issue may later be split into separate CVEs if the error proves independent across the different TAR parser implementations.

4.3 CVSS 2.0 Medium EPSS 94% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial ITSF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityIt is a detection bypass with no confirmed exploitation and only medium CVSS impact, but it affects widely deployed antivirus engines and carries a very high EPSS score.

What it is

The TAR file parser in Quick Heal 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 fails to correctly handle a POSIX TAR file beginning with an ITSF character sequence, allowing malware to evade detection. This matters because a scanner that misses a malicious archive gives false assurance while the payload reaches the endpoint. The record notes the issue may later be split into separate CVEs if the error proves independent across the different TAR parser implementations.

Impact

An attacker can deliver a malicious TAR archive that the affected antivirus products do not flag, so malware reaches the target host without the scanner raising an alert. The flaw is a detection bypass, not code execution in the scanner itself.

Attack surface

Reached remotely over the network by supplying a crafted POSIX TAR file to a system whose antivirus scans it; no authentication is required per the AV:N/Au:N vector. Some user or automated action to bring the file into the scan path is implied by AC:M, but the record does not specify the exact delivery mechanism.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is very high (0.94059, 99.8th percentile), indicating strong predicted likelihood of exploitation activity, though that score should be treated cautiously for a 2012 detection-bypass issue.

What to do

  • Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm current patched builds with each vendor.
  • Do not rely on the affected scanner versions as the sole malware control; layer endpoint detection and email/web gateway scanning from other engines.
  • Block or quarantine TAR archives at the perimeter and inspect them with a parser that handles the ITSF prefix correctly.
  • Retire or upgrade end-of-life products such as Quick Heal 11.00, NOD32 5795, Norman 6.06.12, and Rising 22.83.00.03, which are long unsupported.
  • Alert on TAR files whose leading bytes are the ITSF sequence and treat them as suspicious.

Detection

  • Search file-scan and gateway logs for TAR archives beginning with the ITSF byte sequence.
  • Correlate antivirus scan results with subsequent process execution from extracted archive contents to catch missed payloads.
  • Monitor for the affected product versions in asset inventory and flag hosts still running them.
  • Review email and web download logs for TAR attachments or downloads that passed scanning without a verdict.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1422 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10180Eset cyber security interpretation conflict vulnerabilityThe ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart S…EPSS 1.7%9.3CVE-2008-5539Rising-global rising antivirus improper input validation vulnerabilityRISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware …EPSS 10%9.3CVE-2008-5534Eset nod32 antivirus improper input validation vulnerabilityESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML…EPSS 3.5%9.3CVE-2008-5535Norman antivirus \& antispyware improper input validation vulnerabilityNorman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placin…EPSS 3.0%8.6CVE-2023-5594Eset endpoint antivirus improper certificate validation vulnerabilityImproper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …EPSS 0.38%7.8CVE-2024-0353Eset endpoint antivirus improper privilege management vulnerabilityLocal privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…EPSS 0.55%7.8CVE-2021-37851Eset endpoint antivirus vulnerabilityLocal privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run ma…EPSS 0.21%7.8CVE-2021-37852Eset endpoint antivirus improper privilege management vulnerabilityESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2012-1422), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.