SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1426

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection…

MEDIUM 4.3EPSS 90.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 90.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
89.98% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
authentium/command antivirus · cat/quick heal · f-prot/f-prot antivirus · k7computing/antivirus · norman/norman antivirus \& antispyware · rising-global/rising antivirus
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.