← Vulnerability feed

Vulnerability record · CVE-2012-1426 · published 21 March 2012

CVE-2012-1426: Antivirus TAR parser malware detection bypass via crafted POSIX TAR header

Authentium · Command Antivirus

The TAR file parser in multiple antivirus products (Quick Heal 11.00, Command Antivirus 5.2.11.5, F-Prot 4.6.2.117, K7 AntiVirus 9.77.3565, Norman 6.06.12, Rising 22.83.00.03) fails to correctly handle a POSIX TAR file beginning with the byte sequence \42\5A\68, allowing malware to evade detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes it may later be split into separate CVEs if the flaw proves independent across implementations.

4.3 CVSS 2.0 Medium EPSS 90% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 scores it 4.3 (medium) with integrity-only impact and no code execution, but the flaw defeats a security control and EPSS is very high, so it warrants prompt patching rather than emergency action.

What it is

The TAR file parser in multiple antivirus products (Quick Heal 11.00, Command Antivirus 5.2.11.5, F-Prot 4.6.2.117, K7 AntiVirus 9.77.3565, Norman 6.06.12, Rising 22.83.00.03) fails to correctly handle a POSIX TAR file beginning with the byte sequence \42\5A\68, allowing malware to evade detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products provide. The record notes it may later be split into separate CVEs if the flaw proves independent across implementations.

Impact

An attacker can deliver a malicious TAR archive that the affected antivirus engine does not flag, letting malware reach the endpoint undetected. The attacker gains no code execution through this flaw itself; the gain is evasion of the security control.

Attack surface

Reached remotely over the network by supplying a crafted TAR file to the scanning engine, for example through email attachments, downloads or file transfers that the antivirus inspects. No authentication is required (Au:N), but the CVSS vector indicates medium access complexity (AC:M), implying some conditions must be met for the bypass to succeed.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, so there is no confirmed in-the-wild exploitation in this record. EPSS is very high (0.89984, 99.787th percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm patched builds directly with each vendor.
  • Where no fix exists, replace or supplement the affected TAR scanning with a product that correctly parses POSIX TAR headers.
  • Block or quarantine TAR archives at email and web gateways until scanners are confirmed patched.
  • Re-scan historical quarantine and file shares with an unaffected engine to catch archives that previously bypassed detection.
  • Track the NVD note about a possible CVE split and re-check advisories for each vendor separately.

Detection

  • Search file transfer, email gateway and proxy logs for TAR archives whose first bytes are 42 5A 68 (BZh) and inspect them with an alternate engine.
  • Monitor for files that pass antivirus scanning but later trigger endpoint detection or sandbox alerts, indicating a scanner bypass.
  • Audit deployed antivirus versions against the affected builds (Quick Heal 11.00, Command 5.2.11.5, F-Prot 4.6.2.117, K7 9.77.3565, Norman 6.06.12, Rising 22.83.00.03) and flag unpatched hosts.
  • Correlate scanner verdicts with sandbox detonation results for TAR-containing payloads to spot discrepancies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1426 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1783F-prot antivirus improper input validation vulnerabilityMultiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Se…EPSS 3.4%9.8CVE-2017-17699K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17700K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17701K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17464K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002570 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17465K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002574 DeviceIoControl request.EPSS 1.3%9.3CVE-2008-5533K7computing antivirus improper input validation vulnerabilityK7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML …EPSS 3.0%9.3CVE-2008-5535Norman antivirus \& antispyware improper input validation vulnerabilityNorman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placin…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2012-1426), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.