← Vulnerability feed

Vulnerability record · CVE-2012-1423 · published 21 March 2012

CVE-2012-1423: Antivirus TAR parser malware detection bypass via MZ-prefixed POSIX TAR file

Authentium · Command Antivirus

Multiple antivirus products parse POSIX TAR archives in a way that can be tricked by a file beginning with an MZ character sequence, causing the scanner to misclassify or skip the archive contents. This lets malware inside the TAR evade detection by the affected engines. The record covers many separate products and notes the issue may later be split into multiple CVEs.

4.3 CVSS 2.0 Medium EPSS 90% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 base is 4.3 (MEDIUM) and impact is limited to detection bypass, but the very high EPSS and broad product list raise real-world concern.

What it is

Multiple antivirus products parse POSIX TAR archives in a way that can be tricked by a file beginning with an MZ character sequence, causing the scanner to misclassify or skip the archive contents. This lets malware inside the TAR evade detection by the affected engines. The record covers many separate products and notes the issue may later be split into multiple CVEs.

Impact

An attacker can deliver a malicious TAR archive that the affected antivirus engine fails to flag, allowing malware to reach the endpoint undetected. The flaw is a detection bypass, not code execution in the scanner itself.

Attack surface

Reached remotely by supplying a crafted TAR file to the scanning engine, for example through email attachment, download or file transfer. No authentication is required, but some user or automated action to submit the file for scanning is needed (AV:N/AC:M/Au:N).

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is very high (0.8971, 99.78th percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply vendor updates for each affected antivirus product; the record does not list fixed versions, so confirm with the vendor.
  • Where no fix exists, disable or restrict TAR archive scanning reliance and block TAR attachments at the mail and web gateway.
  • Add independent detection layers (network inspection, application allowlisting) so a single AV parser bypass does not leave the endpoint unprotected.
  • Re-scan or quarantine TAR archives with a second engine or sandbox before allowing execution.
  • Track the note that this CVE may be split; monitor vendor advisories for product-specific identifiers.

Detection

  • Alert on TAR archives whose first bytes are the MZ sequence (4D 5A) at file submission or gateway inspection.
  • Monitor for files that pass AV scanning but later execute or drop payloads, indicating a parser bypass.
  • Log and review AV engine version and parser errors on TAR handling across the affected products.
  • Hunt for TAR files arriving via email or download that contain PE executables or scripts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1783F-prot antivirus improper input validation vulnerabilityMultiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Se…EPSS 3.4%9.8CVE-2020-10180Eset cyber security interpretation conflict vulnerabilityThe ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart S…EPSS 1.7%9.3CVE-2008-5534Eset nod32 antivirus improper input validation vulnerabilityESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML…EPSS 3.5%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%8.6CVE-2023-5594Eset endpoint antivirus improper certificate validation vulnerabilityImproper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …EPSS 0.38%7.8CVE-2024-0353Eset endpoint antivirus improper privilege management vulnerabilityLocal privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…EPSS 0.55%7.8CVE-2021-37851Eset endpoint antivirus vulnerabilityLocal privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run ma…EPSS 0.21%7.8CVE-2021-37852Eset endpoint antivirus improper privilege management vulnerabilityESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2012-1423), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.