Trend Micro has been notified of a potential vulnerability in Scan Engine 9.12, 9.2, and 9.5 (VSAPI 9.12, 9.2, and 9.5).
Based on the claim, the vulnerability allows the Scan Engine to return an error code or to execute arbitrary code via crafted compressed file by this evasion attacks (ex: CAB, TAR, RAR compression file). It also claims that the vulnerability affects all Trend Micro products that use the mentioned Scan Engines.
This was first reported by Seclists.org through the article entitled Evasion attacks expoliting file-parsing vulnerabilities in antivirus product.
Trend Micro has confirmed that this is NOT a Scan Engine vulnerability. The malformed samples are neither self-extracting nor auto-executing files. It does not cause infection and does not crash the Scan Engine.
This vulnerability does not affect Trend Micro products that are using the mentioned Scan Engines.