Vulnerability record · CVE-2012-1423 · published 21 March 2012
CVE-2012-1423: Antivirus TAR parser malware detection bypass via MZ-prefixed POSIX TAR file
Authentium · Command Antivirus
Multiple antivirus products parse POSIX TAR archives in a way that can be tricked by a file beginning with an MZ character sequence, causing the scanner to misclassify or skip the archive contents. This lets malware inside the TAR evade detection by the affected engines. The record covers many separate products and notes the issue may later be split into multiple CVEs.
Description
The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 base is 4.3 (MEDIUM) and impact is limited to detection bypass, but the very high EPSS and broad product list raise real-world concern.
What it is
Multiple antivirus products parse POSIX TAR archives in a way that can be tricked by a file beginning with an MZ character sequence, causing the scanner to misclassify or skip the archive contents. This lets malware inside the TAR evade detection by the affected engines. The record covers many separate products and notes the issue may later be split into multiple CVEs.
Impact
An attacker can deliver a malicious TAR archive that the affected antivirus engine fails to flag, allowing malware to reach the endpoint undetected. The flaw is a detection bypass, not code execution in the scanner itself.
Attack surface
Reached remotely by supplying a crafted TAR file to the scanning engine, for example through email attachment, download or file transfer. No authentication is required, but some user or automated action to submit the file for scanning is needed (AV:N/AC:M/Au:N).
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is very high (0.8971, 99.78th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply vendor updates for each affected antivirus product; the record does not list fixed versions, so confirm with the vendor.
- Where no fix exists, disable or restrict TAR archive scanning reliance and block TAR attachments at the mail and web gateway.
- Add independent detection layers (network inspection, application allowlisting) so a single AV parser bypass does not leave the endpoint unprotected.
- Re-scan or quarantine TAR archives with a second engine or sandbox before allowing execution.
- Track the note that this CVE may be split; monitor vendor advisories for product-specific identifiers.
Detection
- Alert on TAR archives whose first bytes are the MZ sequence (4D 5A) at file submission or gateway inspection.
- Monitor for files that pass AV scanning but later execute or drop payloads, indicating a parser bypass.
- Log and review AV engine version and parser errors on TAR handling across the affected products.
- Hunt for TAR files arriving via email or download that contain PE executables or scripts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1423 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1423), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.