← Vulnerability feed

Vulnerability record · CVE-2012-1425 · published 21 March 2012

CVE-2012-1425: Multiple antivirus TAR parsers allow malware detection bypass via crafted POSIX TAR header

Antiy · Avl Sdk

The TAR file parser in numerous antivirus products mishandles POSIX TAR files whose initial bytes are the \50\4B\03\04 sequence, letting a crafted archive evade malware detection. Because the flaw affects the scanning engine itself, a malicious file can pass through the antivirus layer undetected. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across implementations.

4.3 CVSS 2.0 Medium EPSS 93% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
16Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw defeats malware detection across many widely deployed antivirus engines and has a very high EPSS score, though it requires a crafted archive and is not known to be actively exploited per KEV.

What it is

The TAR file parser in numerous antivirus products mishandles POSIX TAR files whose initial bytes are the \50\4B\03\04 sequence, letting a crafted archive evade malware detection. Because the flaw affects the scanning engine itself, a malicious file can pass through the antivirus layer undetected. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across implementations.

Impact

An attacker can deliver malware inside a specially crafted TAR archive that the affected antivirus engine fails to flag, defeating the primary detection control. The CVSS vector shows no confidentiality or availability impact, only partial integrity impact.

Attack surface

Reachable remotely over the network (AV:N) with no authentication required (Au:N), but exploitation requires moderate complexity (AC:M), likely involving delivery of a crafted TAR file to a system where the affected scanner processes it. No user interaction is specified in the vector.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.93199, 99.829th percentile), indicating strong predicted exploitation activity; reference tags are empty and provide no exploit-status detail.

What to do

  • Apply vendor updates or engine/signature updates for all listed antivirus products; treat the affected versions as unsupported and migrate to current releases.
  • Do not rely on a single antivirus engine for TAR archive inspection; add a second, independent scanner or sandbox detonation for archive contents.
  • Block or quarantine inbound TAR archives at email and web gateways unless explicitly required by business process.
  • Re-scan historical TAR archives with an updated engine to identify files that may have bypassed detection.
  • Monitor vendor advisories for the potential CVE split noted in the record and track each resulting identifier separately.

Detection

  • Search file transfer and email logs for TAR archives whose first bytes are 50 4B 03 04 (PK\x03\x04) and alert on this mismatch between TAR extension and ZIP-like magic.
  • Hunt for TAR files that pass through the antivirus pipeline without a corresponding detection verdict, especially from external sources.
  • Correlate endpoint telemetry for archive extraction followed by execution of newly written files that lack prior antivirus verdicts.
  • Review scanner logs for parsing errors or skipped files on TAR inputs across the affected product versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2974Avira antivir vulnerabilityBuffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a craft…EPSS 7.5%9.8CVE-2020-10180Eset cyber security interpretation conflict vulnerabilityThe ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart S…EPSS 1.7%9.3CVE-2008-5534Eset nod32 antivirus improper input validation vulnerabilityESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML…EPSS 3.5%8.6CVE-2023-5594Eset endpoint antivirus improper certificate validation vulnerabilityImproper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …EPSS 0.38%7.8CVE-2024-0353Eset endpoint antivirus improper privilege management vulnerabilityLocal privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…EPSS 0.55%7.8CVE-2021-37851Eset endpoint antivirus vulnerabilityLocal privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run ma…EPSS 0.21%7.8CVE-2021-37852Eset endpoint antivirus improper privilege management vulnerabilityESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …EPSS 0.60%7.8CVE-2020-11446Eset antivirus and antispyware link following vulnerabilityESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2012-1425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.