Cyber Security News

WinZip Vulnerability Allows Remote Attackers to Execute Arbitrary Code

A newly discovered vulnerability in WinZip, a popular file compression and archiving utility, has raised alarms among cybersecurity experts.

Identified as CVE-2025-1240, this critical flaw allows remote attackers to execute arbitrary code on a victim’s system under specific conditions. Users are strongly advised to update their software to mitigate the risk.

Key Details of the Vulnerability

The vulnerability, disclosed under ZDI-25-047 and ZDI-CAN-24986, stems from an issue in the parsing of 7Z files—a file format commonly associated with compressed archives.

Improper validation of user-supplied data can result in an out-of-bounds write, enabling attackers to potentially execute malicious code in the current process.

This flaw has earned a CVSS score of 7.8 (High), reflecting its severity and potential impact on confidentiality, integrity, and availability.

For the attack to succeed, user interaction is required, such as opening a malicious 7Z file or visiting a hosting webpage.

Despite requiring user interaction, the possibility of executing arbitrary code makes this vulnerability highly dangerous, particularly as it could lead to full system compromise if exploited successfully.

As per a report by Zero Day Initiative, the vulnerability was initially reported to the vendor, WinZip Computing, on September 4, 2024. 

Following months of investigation and remediation efforts, an official patch was released as part of WinZip 29.0. 

The advisory was publicly disclosed on January 20, 2025, and later updated on February 11, 2025, to include further clarifications.

To address the issue, users are strongly urged to update their software to WinZip 29.0 or later.

The update incorporates fixes to the parsing mechanism, ensuring better validation and secure handling of 7Z files.

The discovery of the flaw has been credited to an anonymous researcher.

The incident highlights the persistent need to ensure software security, particularly for widely used utilities like WinZip.

As cyber threats evolve, users must remain vigilant and proactive in applying security patches.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India

Check Point Software Technologies Ltd. has announced plans to establish its inaugural Asia-Pacific Research and…

6 hours ago

PoC Exploit Released for Ivanti Endpoint Manager Vulnerabilities

A recent investigation into Ivanti Endpoint Manager (EPM) has uncovered four critical vulnerabilities that could…

6 hours ago

Ransomware Trends 2025 – What’s new

As of February 2025, ransomware remains a formidable cyber threat, evolving in complexity and scale.…

6 hours ago

Hackers Delivering Malware Bundled with Fake Job Interview Challenges

ESET researchers have uncovered a series of malicious activities orchestrated by a North Korea-aligned group…

6 hours ago

New Bookworm Malware Using SLL Sideloading Technique To Windows

Cybersecurity researchers from Palo Alto Networks' Unit 42 disclosed the resurgence of the Bookworm malware,…

6 hours ago

Fake Chrome Update Delivers DriverEasy Malware by Abusing Dropbox

A recent investigation has uncovered a malicious application, DriverEasy, masquerading as a legitimate Google Chrome…

7 hours ago