Vulnerability record · CVE-2012-1428 · published 21 March 2012
CVE-2012-1428: Quick Heal, Norman, Sophos TAR parser malware detection bypass
Cat · Quick Heal
The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 can be tricked into skipping malware detection when scanning a POSIX TAR file containing a \4a\46\49\46 character sequence at a specific location. Because the parser misreads the archive, malicious content inside the TAR can pass through the scanner unnoticed, undermining the core function of the antivirus product.
Description
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw weakens malware detection but requires a crafted archive and does not by itself grant code execution, and no confirmed in-the-wild exploitation is documented.
What it is
The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 can be tricked into skipping malware detection when scanning a POSIX TAR file containing a \4a\46\49\46 character sequence at a specific location. Because the parser misreads the archive, malicious content inside the TAR can pass through the scanner unnoticed, undermining the core function of the antivirus product.
Impact
An attacker gains the ability to deliver malware that the affected scanners will not flag, so a malicious TAR can reach the endpoint or user without triggering detection. Integrity of the scanning result is lost; there is no direct code execution or data disclosure from the flaw itself.
Attack surface
Reached remotely by supplying a crafted TAR file to the antivirus scanner, typically as an email attachment or downloaded archive. No authentication is required, but the attack depends on the target scanner processing the file, which may involve some user action to open or scan it.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, though EPSS is very high (0.876, 99.7th percentile), suggesting elevated predicted exploitation activity. The record does not confirm in-the-wild use.
What to do
- Apply vendor updates for Quick Heal, Norman, and Sophos products; if no fix is available, upgrade to a supported release.
- Block or quarantine TAR archives at the email and web gateway until scanners are confirmed patched.
- Add independent archive inspection or sandboxing in front of the antivirus scanner for TAR content.
- Restrict user ability to open untrusted archives and reinforce attachment handling policy.
Detection
- Monitor scanner logs for TAR files that are opened but produce no detection verdict, especially with unusual byte sequences.
- Hunt for TAR archives containing the \4a\46\49\46 sequence near the start of file data.
- Correlate endpoint telemetry for archive extraction followed by execution of files that the antivirus did not flag.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1428 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1428), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.