Vulnerability record · CVE-2012-1461 · published 21 March 2012
CVE-2012-1461: Gzip parser in multiple antivirus products allows malware detection bypass
Anti Virus · Vba32
The Gzip file parser in numerous antivirus and anti-malware products mishandles .tar.gz files containing multiple compressed streams, allowing a crafted archive to evade malware detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products are meant to provide. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Description
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw only bypasses detection rather than granting code execution, but it affects a very broad set of security products and carries a high EPSS score.
What it is
The Gzip file parser in numerous antivirus and anti-malware products mishandles .tar.gz files containing multiple compressed streams, allowing a crafted archive to evade malware detection. Because the affected component is the scanner itself, a bypass undermines the core protection these products are meant to provide. The record notes it may later be split into separate CVEs if the error proves independent across parser implementations.
Impact
An attacker can deliver malware inside a specially crafted .tar.gz that the affected scanner fails to detect, so malicious content reaches the endpoint or gateway unchecked. The attacker gains no code execution from the flaw itself, only evasion of the detection layer.
Attack surface
Reached remotely by supplying a crafted .tar.gz file to a scanning product, such as through email, web or file transfer inspection. No authentication is required, but the CVSS vector indicates medium attack complexity and no user interaction is specified.
Exploitation
Not listed in CISA KEV and no reference tags indicate known exploitation, though EPSS is very high at roughly 0.917 (99.8th percentile), suggesting elevated predicted likelihood. No public exploit or in-the-wild use is confirmed by the supplied record.
What to do
- Apply vendor updates for the affected antivirus and anti-malware products; this is a 2012 issue, so confirm current versions are not still affected.
- Where a patch is unavailable, disable or restrict automatic scanning of .tar.gz archives or route them to a secondary detection engine.
- Layer detection with a second, independently implemented scanner so a single parser bypass does not result in a miss.
- Block or quarantine inbound .tar.gz attachments and downloads at the gateway until scanners are confirmed fixed.
- Re-scan historical quarantine and mail archives with updated engines to catch previously missed multi-stream archives.
Detection
- Monitor scanner logs for .tar.gz files that pass inspection but later execute or trigger endpoint alerts.
- Hunt for archives containing multiple gzip streams or concatenated members reaching mail and web gateways.
- Correlate gateway scan verdicts with endpoint detection events to find files that bypassed the initial scan.
- Track vendor advisories and version inventories to identify endpoints still running the listed 2012-era engine versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1461 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1461), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.