← Vulnerability feed

Vulnerability record · CVE-2012-1460 · published 21 March 2012

CVE-2012-1460: Gzip parser in multiple antivirus engines allows malware detection bypass

Aladdin · Esafe

The Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection. The flaw affects multiple independent engines (Antiy AVL SDK, Quick Heal, Command Antivirus, eSafe, F-Prot, Jiangmin, K7, VBA32), so a single crafted archive can slip past several scanners at once. It matters because detection bypass undermines the core protective function of these products.

4.3 CVSS 2.0 Medium EPSS 94% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityIt is a detection bypass rather than direct code execution (CVSS 4.3), but it affects many widely deployed scanners and carries a very high EPSS score.

What it is

The Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection. The flaw affects multiple independent engines (Antiy AVL SDK, Quick Heal, Command Antivirus, eSafe, F-Prot, Jiangmin, K7, VBA32), so a single crafted archive can slip past several scanners at once. It matters because detection bypass undermines the core protective function of these products.

Impact

An attacker can deliver a malicious .tar.gz that the affected scanner fails to flag, letting malware reach the endpoint or mail gateway undetected. The attacker gains no code execution from the flaw itself, only evasion of the antivirus check.

Attack surface

Reached remotely by supplying a crafted .tar.gz file to a system whose antivirus engine parses it, such as through email attachments, web downloads or file uploads. No authentication is required, but some user or automated action to deliver and scan the file is needed (AV:N/AC:M/Au:N).

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, though EPSS is very high (0.944, 99.8th percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply vendor updates for each affected antivirus engine; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix exists, disable or restrict automatic parsing of .tar.gz archives by the scanner and route them to a secondary inspection tool.
  • Add independent detection layers (sandboxing, YARA or signature checks outside the affected parser) so a single bypass does not result in delivery.
  • Block or quarantine .tar.gz attachments at the mail and web gateway unless explicitly required.
  • Track the NVD note that this CVE may be split per implementation and re-check advisories for each product.

Detection

  • Monitor for .tar.gz files with trailing stray bytes after the gzip stream and alert on scanner results that return clean for such files.
  • Correlate antivirus scan logs with file delivery events to find archives that pass scanning but later execute or drop payloads.
  • Hunt for repeated submissions of malformed .tar.gz archives to mail gateways or upload endpoints from the same source.
  • Review endpoint telemetry for processes spawned from extracted archive contents that were never flagged by the local scanner.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%7.1CVE-2024-23440Anti-virus vba32 out-of-bounds read vulnerabilityVba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up…EPSS 0.21%7.1CVE-2024-23439Anti-virus vba32 out-of-bounds read vulnerabilityVba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0…EPSS 0.21%5.5CVE-2024-23441Anti-virus vba32 null pointer dereference vulnerabilityVba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.EPSS 0.24%5.1CVE-2005-3231Cat quick heal vulnerabilityMultiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable …EPSS 14%5.0CVE-2005-3399Cat quick heal vulnerabilityMultiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…EPSS 7.8%4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1460), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.