Vulnerability record · CVE-2012-1456 · published 21 March 2012
CVE-2012-1456: Antivirus TAR parsers bypassed by appended ZIP file
Aladdin · Esafe
Multiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore deliver a malicious ZIP payload that the scanner does not inspect, undermining the core function of the endpoint protection. The record notes it may later be split into separate CVEs if the error proves independent across implementations.
Description
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityIt is a detection bypass requiring a crafted file and medium attack complexity, with no KEV listing, though the very high EPSS and broad product exposure keep it relevant.
What it is
Multiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore deliver a malicious ZIP payload that the scanner does not inspect, undermining the core function of the endpoint protection. The record notes it may later be split into separate CVEs if the error proves independent across implementations.
Impact
An attacker gains a way to smuggle malware past the affected antivirus engines, so malicious content reaches the host without being flagged. The flaw is a detection bypass, not code execution in the scanner itself.
Attack surface
Reached remotely by supplying a crafted TAR file with an appended ZIP, typically through file scanning or mail/web content inspection. No authentication is required; the CVSS vector AV:N/AC:M/Au:N indicates network delivery with medium complexity and no user account, though some user action to open or scan the file is implied.
Exploitation
Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is very high (0.99934, 99.97th percentile), suggesting elevated predicted likelihood. No public exploit details are provided in the record.
What to do
- Apply vendor updates for the affected antivirus engines; the record does not list fixed versions, so confirm with each vendor.
- Where no fix exists, disable or restrict TAR scanning paths or route suspicious archives to a second, independent scanner.
- Enforce layered detection (network and endpoint) so a single parser bypass does not equal full evasion.
- Block or quarantine TAR files with appended ZIP data at mail and web gateways.
- Track vendor advisories for the possible CVE split, as fixes may be issued per product.
Detection
- Alert on TAR files containing appended ZIP signatures (PK\x03\x04 after the TAR end-of-archive marker).
- Monitor for archive files that pass gateway inspection but are flagged by a second engine or sandbox.
- Log and review antivirus scan results for TAR/ZIP polyglot files that return clean despite embedded executables.
- Correlate endpoint detections of ZIP-borne malware with prior clean scans of the same file.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1456 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1456), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.