← Vulnerability feed

Vulnerability record · CVE-2012-1424 · published 21 March 2012

CVE-2012-1424: Antivirus TAR parser malware detection bypass via crafted POSIX TAR

Antiy · Avl Sdk

The TAR file parser in multiple antivirus products (Antiy AVL SDK, Quick Heal, Jiangmin, Norman, PC Tools, Sophos) fails to correctly handle a POSIX TAR file containing a specific \19\04\00\10 character sequence, allowing malware detection to be bypassed. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus undetected, undermining the core protection these products provide. The record notes it may later be split into separate CVEs if the error is shown to occur independently across the different TAR parser implementations.

4.3 CVSS 2.0 Medium EPSS 87% · top 0.3% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 base score is 4.3 (MEDIUM) with integrity-only impact, but the flaw defeats malware detection across several widely used antivirus products and EPSS is very high.

What it is

The TAR file parser in multiple antivirus products (Antiy AVL SDK, Quick Heal, Jiangmin, Norman, PC Tools, Sophos) fails to correctly handle a POSIX TAR file containing a specific \19\04\00\10 character sequence, allowing malware detection to be bypassed. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus undetected, undermining the core protection these products provide. The record notes it may later be split into separate CVEs if the error is shown to occur independently across the different TAR parser implementations.

Impact

An attacker can deliver a malicious TAR archive that evades detection by the affected antivirus products, allowing malware to reach the target system without being flagged. The direct gain is detection bypass rather than code execution or data access on the scanner itself.

Attack surface

The flaw is reached remotely over the network (AV:N) by supplying a crafted POSIX TAR file to the affected scanning engine; no authentication is required (Au:N). Some user interaction is implied by the AC:M vector, consistent with a victim opening or scanning the malicious archive.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.87288, 99.7th percentile), suggesting elevated predicted exploitation activity. The record does not confirm in-the-wild exploitation.

What to do

  • Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm patch availability with each vendor (Antiy, Quick Heal, Jiangmin, Norman, PC Tools, Sophos).
  • Where patching is unavailable, supplement the affected scanner with a second, independently maintained detection engine for TAR archives.
  • Block or quarantine inbound TAR archives at email and web gateways until scanners are confirmed patched.
  • Restrict user handling of untrusted archives and enforce attachment filtering policies.
  • Track the NVD record for a possible CVE split, which may change which products and fixes apply.

Detection

  • Monitor for TAR archives containing the \19\04\00\10 byte sequence at the described location in file submission and gateway logs.
  • Correlate endpoint and gateway scan results for archives that pass one engine but are flagged by another.
  • Alert on TAR files delivered from external sources that trigger no detection across the affected product set.
  • Review historical quarantine and scan logs for TAR files that were allowed through during the exposure window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-5535Norman antivirus \& antispyware improper input validation vulnerabilityNorman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placin…EPSS 3.0%7.8CVE-2023-1626Jiangmin antivirus memory buffer overflow vulnerabilityA vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been declared as critical. This vulnerability affects unknown code in the libra…EPSS 0.34%7.8CVE-2023-1629Jiangmin antivirus memory buffer overflow vulnerabilityA vulnerability classified as critical was found in JiangMin Antivirus 16.2.2022.418. Affected by this vulnerability is the function 0x222010 in the …EPSS 0.43%5.5CVE-2023-1628Jiangmin antivirus null pointer dereference vulnerabilityA vulnerability classified as problematic has been found in Jianming Antivirus 16.2.2022.418. Affected is an unknown function in the library kvcore.s…EPSS 0.32%5.5CVE-2023-1630Jiangmin antivirus improper resource shutdown vulnerabilityA vulnerability, which was classified as problematic, has been found in JiangMin Antivirus 16.2.2022.418. Affected by this issue is the function 0x22…EPSS 0.32%5.5CVE-2023-1631Jiangmin antivirus null pointer dereference vulnerabilityA vulnerability, which was classified as problematic, was found in JiangMin Antivirus 16.2.2022.418. This affects the function 0x222010 in the librar…EPSS 0.35%5.5CVE-2023-1627Jiangmin antivirus improper resource shutdown vulnerabilityA vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been rated as problematic. This issue affects some unknown processing in the li…EPSS 0.32%5.5CVE-2020-14955Jiangmin antivirus improper input validation vulnerabilityIn Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified oth…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2012-1424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.