PT-2024-6334 · Winzip · Winzip
Gothburz
+1
·
Published
2024-09-17
·
Updated
2025-05-06
·
CVE-2024-8811
7.8
High
Base vector | Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WinZip versions prior to 29.0
Description:
The issue is related to a Mark-of-the-Web Bypass Vulnerability in WinZip, allowing remote attackers to bypass the Mark-of-the-Web protection mechanism. This can be exploited when a user opens a malicious file or visits a malicious page, potentially leading to arbitrary code execution in the context of the current user. The vulnerability exists within the handling of archive files, where WinZip removes the Mark-of-the-Web from the archive file and the extracted files lack the Mark-of-the-Web.
Recommendations:
For versions prior to 29.0, update to version 29.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of WinZip for handling archive files until a patch is applied. Restrict access to potentially malicious files and websites to minimize the risk of exploitation.
Fix
RCE
Protection Mechanism Failure
Related Identifiers
Affected Products
References · 27
- https://bdu.fstec.ru/vul/2024-07371 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2024-8811 · Security Note
- https://zerodayinitiative.com/advisories/ZDI-25-047 · Security Note
- https://zerodayinitiative.com/advisories/ZDI-24-1234 · Security Note
- https://t.me/pentestingnews/53541 · Telegram Post
- https://t.me/cvenotify/106278 · Telegram Post
- https://twitter.com/the_yellow_fall/status/1860151510052794805 · Twitter Post
- https://t.me/tomhunter/2721 · Telegram Post
- https://vuldb.com/sv/?id.277821 · Note
- https://twitter.com/Dinosn/status/1860175451647541609 · Twitter Post
- https://twitter.com/SystemTek_UK/status/1836114233248858140 · Twitter Post
- https://t.me/thedarkwebinformer/16848 · Telegram Post
- https://cybersecurity-help.cz/vulnerabilities/97461 · Note
- https://twitter.com/CVEnew/status/1912201816856838329 · Twitter Post
- https://t.me/true_secator/6979 · Telegram Post