← Vulnerability feed

Vulnerability record · CVE-2012-1461 · published 21 March 2012

CVE-2012-1461: Gzip parser in multiple antivirus products allows malware detection bypass

Anti Virus · Vba32

The Gzip file parser in numerous antivirus and anti-malware products mishandles .tar.gz files containing multiple compressed streams, allowing a crafted archive to evade malware detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products are meant to provide. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

4.3 CVSS 2.0 Medium EPSS 92% · top 0.2% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
20Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw only bypasses detection rather than granting code execution, but it affects a very broad set of security products and carries a high EPSS score.

What it is

The Gzip file parser in numerous antivirus and anti-malware products mishandles .tar.gz files containing multiple compressed streams, allowing a crafted archive to evade malware detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products are meant to provide. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.

Impact

An attacker can deliver malware inside a specially crafted .tar.gz that the affected scanner fails to detect, so malicious content reaches the endpoint or gateway unchecked. The attacker gains no code execution from the flaw itself, only evasion of the detection layer.

Attack surface

Reached remotely by supplying a crafted .tar.gz file to a scanning product, such as through email, web or file transfer inspection. No authentication is required, but the CVSS vector indicates medium attack complexity and no user interaction is specified.

Exploitation

Not listed in CISA KEV and no reference tags indicate known exploitation, though EPSS is very high at roughly 0.917 (99.8th percentile), suggesting elevated predicted likelihood. No public exploit or in-the-wild use is confirmed by the supplied record.

What to do

  • Apply vendor updates for the affected antivirus and anti-malware products; this is a 2012 issue, so confirm current versions are not still affected.
  • Where a patch is unavailable, disable or restrict automatic scanning of .tar.gz archives or route them to a secondary detection engine.
  • Layer detection with a second, independently implemented scanner so a single parser bypass does not result in a miss.
  • Block or quarantine inbound .tar.gz attachments and downloads at the gateway until scanners are confirmed fixed.
  • Re-scan historical quarantine and mail archives with updated engines to catch previously missed multi-stream archives.

Detection

  • Monitor scanner logs for .tar.gz files that pass inspection but later execute or trigger endpoint alerts.
  • Hunt for archives containing multiple gzip streams or concatenated members reaching mail and web gateways.
  • Correlate gateway scan verdicts with endpoint detection events to find files that bypassed the initial scan.
  • Track vendor advisories and version inventories to identify endpoints still running the listed 2012-era engine versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1461 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1784Avg anti-virus improper input validation vulnerabilityThe AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition,…EPSS 3.4%9.3CVE-2008-5409Bitdefender antivirus memory buffer overflow vulnerabilityUnspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, an…EPSS 11%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%7.5CVE-2019-7651Emsisoft anti-malware vulnerabilityEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEV…EPSS 4.9%7.1CVE-2024-23440Anti-virus vba32 out-of-bounds read vulnerabilityVba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up…EPSS 0.21%7.1CVE-2024-23439Anti-virus vba32 out-of-bounds read vulnerabilityVba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0…EPSS 0.21%5.5CVE-2024-23441Anti-virus vba32 null pointer dereference vulnerabilityVba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.EPSS 0.24%4.3CVE-2012-1457Antivirus TAR parser malware detection bypass via oversized length fieldThe TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size…EPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1461), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.