Vulnerability record · CVE-2012-1426 · published 21 March 2012
CVE-2012-1426: Antivirus TAR parser malware detection bypass via crafted POSIX TAR header
Authentium · Command Antivirus
The TAR file parser in multiple antivirus products (Quick Heal 11.00, Command Antivirus 5.2.11.5, F-Prot 4.6.2.117, K7 AntiVirus 9.77.3565, Norman 6.06.12, Rising 22.83.00.03) fails to correctly handle a POSIX TAR file beginning with the byte sequence \42\5A\68, allowing malware to evade detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes it may later be split into separate CVEs if the flaw proves independent across implementations.
Description
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 scores it 4.3 (medium) with integrity-only impact and no code execution, but the flaw defeats a security control and EPSS is very high, so it warrants prompt patching rather than emergency action.
What it is
The TAR file parser in multiple antivirus products (Quick Heal 11.00, Command Antivirus 5.2.11.5, F-Prot 4.6.2.117, K7 AntiVirus 9.77.3565, Norman 6.06.12, Rising 22.83.00.03) fails to correctly handle a POSIX TAR file beginning with the byte sequence \42\5A\68, allowing malware to evade detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes it may later be split into separate CVEs if the flaw proves independent across implementations.
Impact
An attacker can deliver a malicious TAR archive that the affected antivirus engine does not flag, letting malware reach the endpoint undetected. The attacker gains no code execution through this flaw itself; the gain is evasion of the security control.
Attack surface
Reached remotely over the network by supplying a crafted TAR file to the scanning engine, for example through email attachments, downloads or file transfers that the antivirus inspects. No authentication is required (Au:N), but the CVSS vector indicates medium access complexity (AC:M), implying some conditions must be met for the bypass to succeed.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, so there is no confirmed in-the-wild exploitation in this record. EPSS is very high (0.89984, 99.787th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm patched builds directly with each vendor.
- Where no fix exists, replace or supplement the affected TAR scanning with a product that correctly parses POSIX TAR headers.
- Block or quarantine TAR archives at email and web gateways until scanners are confirmed patched.
- Re-scan historical quarantine and file shares with an unaffected engine to catch archives that previously bypassed detection.
- Track the NVD note about a possible CVE split and re-check advisories for each vendor separately.
Detection
- Search file transfer, email gateway and proxy logs for TAR archives whose first bytes are 42 5A 68 (BZh) and inspect them with an alternate engine.
- Monitor for files that pass antivirus scanning but later trigger endpoint detection or sandbox alerts, indicating a scanner bypass.
- Audit deployed antivirus versions against the affected builds (Quick Heal 11.00, Command 5.2.11.5, F-Prot 4.6.2.117, K7 9.77.3565, Norman 6.06.12, Rising 22.83.00.03) and flag unpatched hosts.
- Correlate scanner verdicts with sandbox detonation results for TAR-containing payloads to spot discrepancies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1426 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1426), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.