logo

WinZip Vulnerability Allows Remote Attackers to Execute Arbitrary Code

ID: d7f47a91-ea98-5a1e-8d72-18414ec25602

STIX ID: report--d7f47a91-ea98-5a1e-8d72-18414ec25602

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-02-14

Date Updated: 2026-04-22

Author: Divya

...
...

A critical vulnerability (CVE-2025-1240) in WinZip's 7Z parsing was disclosed by ZDI, leading to an out-of-bounds write and potential remote code execution (CVSS 7.8). The issue requires user interaction (opening a malicious 7Z or visiting a hosting page); it was reported in 2024 and patched in WinZip 29.0, and users are urged to update to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.