PT-2025-16367 · Winzip · Winzip
Enis Aksu
·
Published
2025-04-15
·
Updated
2025-05-06
·
CVE-2025-33028
6.4
Medium
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
WinZip versions prior to 29.0
Description:
The issue is related to the handling of archived files in WinZip, allowing attackers to bypass the Mark-of-the-Web protection mechanism. This can be exploited when a user extracts files from a crafted archive that bears the Mark-of-the-Web, as WinZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this to execute arbitrary code in the context of the current user. The exploitation requires user interaction, such as visiting a malicious page or opening a malicious file.
Recommendations:
For versions prior to 29.0, consider disabling the handling of archived files with the Mark-of-the-Web until a patch is available. Restrict access to potentially malicious archives to minimize the risk of exploitation. Avoid using WinZip to extract files from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Weakness Enumeration
Related Identifiers
Affected Products
References · 23
- 🔥 https://github.com/EnisAksu/Argonis/blob/main/CVEs/CVE-2025-33028%20%28WinZip%29/CVE-2025-33028.md⭐ 7 🔗 1 · Exploit
- https://osv.dev/vulnerability/CVE-2025-33028 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-04855 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-33028 · Security Note
- https://github.com/EnisAksu/Argonis/commit/5e1ff4e5f4fdb3f32aab465f7b429e0b91299d1d⭐ 7 🔗 1 · Note
- https://twitter.com/dailytechonx/status/1914808937440035099 · Twitter Post
- https://twitter.com/ForesietTFeed/status/1918252351174939075 · Twitter Post
- https://t.me/thedarkwebinformer/16848 · Telegram Post
- https://kb.winzip.com/help/help_whatsnew.htm · Note
- https://twitter.com/CVEnew/status/1912201816856838329 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1k5ve1w/top_10_trending_cves_23042025 · Reddit Post
- https://t.me/cvenotify/120912 · Telegram Post
- https://twitter.com/VulmonFeeds/status/1912265252827176972 · Twitter Post
- https://twitter.com/the_yellow_fall/status/1914479540564607411 · Twitter Post
- https://twitter.com/samilaiho/status/1914546430632403074 · Twitter Post