← Vulnerability feed

Vulnerability record · CVE-2012-1427 · published 21 March 2012

CVE-2012-1427: Quick Heal, Norman, Sophos TAR parser malware detection bypass

Cat · Quick Heal

The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 can be tricked by a POSIX TAR file containing a specific character sequence (\57\69\6E\5A\69\70) at a certain location. This lets a crafted archive evade malware detection, so malicious content inside the TAR may reach the user or system without being flagged. The record notes it may later be split into multiple CVEs if the flaw is shown to occur independently in different TAR parser implementations.

4.3 CVSS 2.0 Medium EPSS 88% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS 2.0 is 4.3 (MEDIUM) and impact is limited to detection bypass, but the high EPSS score and antivirus-evasion nature warrant attention.

What it is

The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 can be tricked by a POSIX TAR file containing a specific character sequence (\57\69\6E\5A\69\70) at a certain location. This lets a crafted archive evade malware detection, so malicious content inside the TAR may reach the user or system without being flagged. The record notes it may later be split into multiple CVEs if the flaw is shown to occur independently in different TAR parser implementations.

Impact

An attacker can bypass the antivirus TAR scanning and deliver malware that the product would otherwise detect. The direct gain is evasion of detection, not code execution or data access on its own.

Attack surface

Reached remotely by supplying a crafted POSIX TAR file to the affected antivirus parser, typically as a file the victim or a scanning pipeline processes. No authentication is required per the CVSS vector (AV:N/AC:M/Au:N), but some user interaction or automated file handling is needed to get the archive scanned.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code. EPSS is high (0.876, 99.7th percentile), suggesting elevated predicted exploitation activity, but the record does not confirm active exploitation.

What to do

  • Apply vendor updates for Quick Heal, Norman Antivirus, and Sophos Anti-Virus; if no fix is available, confirm current status with each vendor.
  • Do not rely on TAR scanning alone; add independent file inspection or sandboxing for archives before they reach endpoints.
  • Block or quarantine untrusted TAR archives at email and web gateways where feasible.
  • Re-scan or re-evaluate previously scanned TAR files with updated signatures and parsers after patching.

Detection

  • Monitor for TAR files containing the byte sequence 57 69 6E 5A 69 70 at the location described in the advisory.
  • Alert on antivirus scan results that show TAR archives passing without expected detection, especially from external sources.
  • Hunt for repeated delivery of TAR archives to endpoints running the affected product versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1427 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6335Sophos anti-virus vulnerabilityMultiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive wit…EPSS 13%9.3CVE-2008-5535Norman antivirus \& antispyware improper input validation vulnerabilityNorman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placin…EPSS 3.0%7.5CVE-2006-0994Sophos anti-virus vulnerabilityMultiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, …EPSS 22%7.5CVE-2005-2768Sophos anti-virus vulnerabilityHeap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote …EPSS 13%7.5CVE-2004-0937Archive zip vulnerabilitySophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…EPSS 15%7.5CVE-2004-0932McAfee Anti-Virus Engine DATS driver bypass via malformed compressed fileThe McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files…EPSS 64%analysed7.5CVE-2004-0933Archive zip vulnerabilityComputer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content M…EPSS 21%7.5CVE-2004-0934Archive zip vulnerabilityKaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whi…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2012-1427), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.