7.8
CVSSv3

CVE-2025-1240

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00136 | KEV: Not Included
Published: 11/02/2025 Updated: 11/02/2025

Vulnerability Summary

WinZip 7Z File Parsing Remote Code Execution Vulnerability in File Handling

WinZip contains a remote code execution vulnerability in its 7Z file parsing mechanism. The flaw stems from improper validation of user-supplied data, which can cause an out-of-bounds write condition. Remote attackers can potentially execute arbitrary code on affected WinZip installations, but user interaction is necessary - such as visiting a malicious webpage or opening a malicious file. An attacker could leverage this vulnerability to run code within the current process context. The vulnerability was identified as ZDI-CAN-24986 and specifically involves writing beyond the allocated buffer during 7Z file parsing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

winzip computing winzip