7.5
CVSSv2

CVE-2008-3442

Published: 01/08/2008 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

WinZip prior to 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle malicious users to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Vulnerable Product Search on Vulmon Subscribe to Product

winzip winzip 10.0

winzip winzip 8.0

winzip winzip 8.1

winzip winzip 9.0

winzip winzip 7.0