VU#976247: Antivirus and Endpoint Detection and Response Archive Scanning Engines may not properly scan malformed zip archives
2026-03-09T20:52:12Z•a0f31412a4a4c0c564313e4c27eada7646b25494d534adc7af7e15d8f72f7e43
antivirus-evasionarbitrary-file-writearchive-evasionauthentication-bypassc/c++code-injectioncommand-injectiondeep-packet-inspectiondenial-of-serviceedr-evasionhardcoded-secretsimage-decoderjwtnodejsopen5gsout-of-boundspath-traversalpdf-libraryprototype-pollutionpythonrcetls-fingerprintviberwebuizip
What happened
This collection of vulnerability notes covers multiple distinct issues across open-source libraries and applications: archive-scanning evasion via malformed ZIP metadata that can hide payloads from antivirus/EDR engines; a TLS handshake fingerprinting flaw in Rakuten Viber’s Cloak proxy (identifiable via DPI); command-injection (RCE) in the MS-Agent framework (CVE-2026-2256); a PyMuPDF 1.26.5 path-traversal leading to arbitrary file write; prototype pollution in CASL Ability (rulesToFields/setByPath); an out-of-bounds read (DoS) in libheif’s uncompressed codec (CVE-2025-65586); and a code-in‑/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- a0f31412a4a4c0c564313e4c27eada7646b25494d534adc7af7e15d8f72f7e43
- Enrichment time
- 2026-03-09T20:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.