Vulnerability record · CVE-2012-1443 · published 21 March 2012
CVE-2012-1443: RAR parser malware detection bypass in multiple antivirus engines
Ahnlab · V3 Internet Security
The RAR file parser in dozens of antivirus products fails to correctly handle a RAR archive whose contents begin with an MZ character sequence, allowing the archive to evade malware detection. Because the same parsing flaw appears across many independent engines, a single crafted archive can slip past layered defenses. The record notes it may later be split into multiple CVEs if the error is shown to occur independently per implementation.
Description
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than granting code execution, and CVSS is 4.3, but the very high EPSS and broad product exposure keep it relevant for defenders.
What it is
The RAR file parser in dozens of antivirus products fails to correctly handle a RAR archive whose contents begin with an MZ character sequence, allowing the archive to evade malware detection. Because the same parsing flaw appears across many independent engines, a single crafted archive can slip past layered defenses. The record notes it may later be split into multiple CVEs if the error is shown to occur independently per implementation.
Impact
An attacker can deliver a malicious RAR archive that the affected scanner does not flag, so malware reaches the endpoint or gateway undetected. The attacker gains no code execution from the flaw itself; the gain is evasion of the detection control.
Attack surface
Reached remotely by sending a crafted RAR file to a scanning engine, whether at a mail or web gateway or on an endpoint. No authentication is required, but the victim must be induced to open or scan the file, so exploitation is user-assisted.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is very high (0.99636, 99.9th percentile), indicating strong predicted likelihood of exploitation activity. No public exploit details are provided in the record.
What to do
- Apply vendor updates for each affected antivirus engine; this is a 2012 flaw, so confirm current versions are in use and no longer affected.
- Do not rely on a single scanning engine for RAR content; add a second engine or a dedicated file-type and content inspection layer.
- Block or quarantine inbound RAR archives at mail and web gateways unless there is a clear business need.
- Inspect archive contents after extraction rather than trusting the scanner's verdict on the container.
- Retire or isolate end-of-life engines listed in the record that no longer receive signature or parser fixes.
Detection
- Alert on RAR archives whose extracted content begins with the MZ header, especially when the archive was not flagged by the scanner.
- Monitor for files that pass antivirus scanning but later execute or drop PE payloads from archive extraction paths.
- Track scanner verdicts for RAR attachments and flag archives that produce no detection but contain executable content.
- Review gateway and endpoint logs for repeated delivery of RAR files from the same sender or source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
35 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1443 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1443), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.