WinZip Vulnerability Allows Remote Attackers to Execute Arbitrary Code
ID: d7f47a91-ea98-5a1e-8d72-18414ec25602
STIX ID: report--d7f47a91-ea98-5a1e-8d72-18414ec25602
Feed Name: GBHackers
Threat Score
A critical vulnerability (CVE-2025-1240) in WinZip's 7Z parsing was disclosed by ZDI, leading to an out-of-bounds write and potential remote code execution (CVSS 7.8). The issue requires user interaction (opening a malicious 7Z or visiting a hosting page); it was reported in 2024 and patched in WinZip 29.0, and users are urged to update to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
