← Vulnerability feed

Vulnerability record · CVE-2012-1456 · published 21 March 2012

CVE-2012-1456: Antivirus TAR parsers bypassed by appended ZIP file

Aladdin · Esafe

Multiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore deliver a malicious ZIP payload that the scanner does not inspect, undermining the core function of the endpoint protection. The record notes it may later be split into separate CVEs if the error proves independent across implementations.

4.3 CVSS 2.0 Medium EPSS 100% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
20Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityIt is a detection bypass requiring a crafted file and medium attack complexity, with no KEV listing, though the very high EPSS and broad product exposure keep it relevant.

What it is

Multiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore deliver a malicious ZIP payload that the scanner does not inspect, undermining the core function of the endpoint protection. The record notes it may later be split into separate CVEs if the error proves independent across implementations.

Impact

An attacker gains a way to smuggle malware past the affected antivirus engines, so malicious content reaches the host without being flagged. The flaw is a detection bypass, not code execution in the scanner itself.

Attack surface

Reached remotely by supplying a crafted TAR file with an appended ZIP, typically through file scanning or mail/web content inspection. No authentication is required; the CVSS vector AV:N/AC:M/Au:N indicates network delivery with medium complexity and no user account, though some user action to open or scan the file is implied.

Exploitation

Not listed in CISA KEV and no reference tags indicate known exploitation, but EPSS is very high (0.99934, 99.97th percentile), suggesting elevated predicted likelihood. No public exploit details are provided in the record.

What to do

  • Apply vendor updates for the affected antivirus engines; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix exists, disable or restrict TAR scanning paths or route suspicious archives to a second, independent scanner.
  • Enforce layered detection (network and endpoint) so a single parser bypass does not equal full evasion.
  • Block or quarantine TAR files with appended ZIP data at mail and web gateways.
  • Track vendor advisories for the possible CVE split, as fixes may be issued per product.

Detection

  • Alert on TAR files containing appended ZIP signatures (PK\x03\x04 after the TAR end-of-archive marker).
  • Monitor for archive files that pass gateway inspection but are flagged by a second engine or sandbox.
  • Log and review antivirus scan results for TAR/ZIP polyglot files that return clean despite embedded executables.
  • Correlate endpoint detections of ZIP-borne malware with prior clean scans of the same file.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1784Avg anti-virus improper input validation vulnerabilityThe AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition,…EPSS 3.4%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2008-0470Comodo antivirus vulnerabilityA certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.EPSS 31%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%5.1CVE-2005-3231Cat quick heal vulnerabilityMultiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable …EPSS 14%5.0CVE-2005-3399Cat quick heal vulnerabilityMultiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…EPSS 7.8%4.3CVE-2012-1454Antivirus ELF parser malware detection bypass via modified ei_versionMultiple antivirus products, including Dr.Web, eSafe, McAfee Gateway, Rising, Fortinet and Panda, parse ELF files in a way that can be evaded by alte…EPSS 88%analysed4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1456), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.