← Vulnerability feed

Vulnerability record · CVE-2012-1443 · published 21 March 2012

CVE-2012-1443: RAR parser malware detection bypass in multiple antivirus engines

Ahnlab · V3 Internet Security

The RAR file parser in dozens of antivirus products fails to correctly handle a RAR archive whose contents begin with an MZ character sequence, allowing the archive to evade malware detection. Because the same parsing flaw appears across many independent engines, a single crafted archive can slip past layered defenses. The record notes it may later be split into multiple CVEs if the error is shown to occur independently per implementation.

4.3 CVSS 2.0 Medium EPSS 100% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
35Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than granting code execution, and CVSS is 4.3, but the very high EPSS and broad product exposure keep it relevant for defenders.

What it is

The RAR file parser in dozens of antivirus products fails to correctly handle a RAR archive whose contents begin with an MZ character sequence, allowing the archive to evade malware detection. Because the same parsing flaw appears across many independent engines, a single crafted archive can slip past layered defenses. The record notes it may later be split into multiple CVEs if the error is shown to occur independently per implementation.

Impact

An attacker can deliver a malicious RAR archive that the affected scanner does not flag, so malware reaches the endpoint or gateway undetected. The attacker gains no code execution from the flaw itself; the gain is evasion of the detection control.

Attack surface

Reached remotely by sending a crafted RAR file to a scanning engine, whether at a mail or web gateway or on an endpoint. No authentication is required, but the victim must be induced to open or scan the file, so exploitation is user-assisted.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is very high (0.99636, 99.9th percentile), indicating strong predicted likelihood of exploitation activity. No public exploit details are provided in the record.

What to do

  • Apply vendor updates for each affected antivirus engine; this is a 2012 flaw, so confirm current versions are in use and no longer affected.
  • Do not rely on a single scanning engine for RAR content; add a second engine or a dedicated file-type and content inspection layer.
  • Block or quarantine inbound RAR archives at mail and web gateways unless there is a clear business need.
  • Inspect archive contents after extraction rather than trusting the scanner's verdict on the container.
  • Retire or isolate end-of-life engines listed in the record that no longer receive signature or parser fixes.

Detection

  • Alert on RAR archives whose extracted content begins with the MZ header, especially when the archive was not flagged by the scanner.
  • Monitor for files that pass antivirus scanning but later execute or drop PE payloads from archive extraction paths.
  • Track scanner verdicts for RAR attachments and flag archives that produce no detection but contain executable content.
  • Review gateway and endpoint logs for repeated delivery of RAR files from the same sender or source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

35 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1443 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-2869Alwil avast antivirus vulnerabilityUnspecified vulnerability in the CHM unpacker in avast! before 4.7.844 has unknown impact and remote attack vectors.EPSS 1.7%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2006-4626Alwil avast antivirus vulnerabilityHeap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file …EPSS 4.7%7.5CVE-2005-2385Alwil avast antivirus vulnerabilityBuffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition …EPSS 4.0%7.5CVE-2005-1719Alwil avast antivirus vulnerabilityUnknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2012-1443), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.