WinZip 7Z File Parsing Remote Code Execution Vulnerability in File Handling
WinZip contains a remote code execution vulnerability in its 7Z file parsing mechanism. The flaw stems from improper validation of user-supplied data, which can cause an out-of-bounds write condition. Remote attackers can potentially execute arbitrary code on affected WinZip installations, but user interaction is necessary - such as visiting a malicious webpage or opening a malicious file. An attacker could leverage this vulnerability to run code within the current process context. The vulnerability was identified as ZDI-CAN-24986 and specifically involves writing beyond the allocated buffer during 7Z file parsing.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
winzip computing winzip |