Vulnerability record · CVE-2012-1425 · published 21 March 2012
CVE-2012-1425: Multiple antivirus TAR parsers allow malware detection bypass via crafted POSIX TAR header
Antiy · Avl Sdk
The TAR file parser in numerous antivirus products mishandles POSIX TAR files whose initial bytes are the \50\4B\03\04 sequence, letting a crafted archive evade malware detection. Because the flaw affects the scanning engine itself, a malicious file can pass through the antivirus layer undetected. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across implementations.
Description
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
high priorityThe flaw defeats malware detection across many widely deployed antivirus engines and has a very high EPSS score, though it requires a crafted archive and is not known to be actively exploited per KEV.
What it is
The TAR file parser in numerous antivirus products mishandles POSIX TAR files whose initial bytes are the \50\4B\03\04 sequence, letting a crafted archive evade malware detection. Because the flaw affects the scanning engine itself, a malicious file can pass through the antivirus layer undetected. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across implementations.
Impact
An attacker can deliver malware inside a specially crafted TAR archive that the affected antivirus engine fails to flag, defeating the primary detection control. The CVSS vector shows no confidentiality or availability impact, only partial integrity impact.
Attack surface
Reachable remotely over the network (AV:N) with no authentication required (Au:N), but exploitation requires moderate complexity (AC:M), likely involving delivery of a crafted TAR file to a system where the affected scanner processes it. No user interaction is specified in the vector.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.93199, 99.829th percentile), indicating strong predicted exploitation activity; reference tags are empty and provide no exploit-status detail.
What to do
- Apply vendor updates or engine/signature updates for all listed antivirus products; treat the affected versions as unsupported and migrate to current releases.
- Do not rely on a single antivirus engine for TAR archive inspection; add a second, independent scanner or sandbox detonation for archive contents.
- Block or quarantine inbound TAR archives at email and web gateways unless explicitly required by business process.
- Re-scan historical TAR archives with an updated engine to identify files that may have bypassed detection.
- Monitor vendor advisories for the potential CVE split noted in the record and track each resulting identifier separately.
Detection
- Search file transfer and email logs for TAR archives whose first bytes are 50 4B 03 04 (PK\x03\x04) and alert on this mismatch between TAR extension and ZIP-like magic.
- Hunt for TAR files that pass through the antivirus pipeline without a corresponding detection verdict, especially from external sources.
- Correlate endpoint telemetry for archive extraction followed by execution of newly written files that lack prior antivirus verdicts.
- Review scanner logs for parsing errors or skipped files on TAR inputs across the affected product versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1425 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.