vendor:
WinZip
by:
ATmaCA
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: WinZip
Affected Version From: WinZip 8.1
Affected Version To: WinZip 9.0 Service Release 1 (SR-1)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2004
WinZip Command Line Local Buffer Overflow
WinZip Command Line Local Buffer Overflow is a vulnerability in WinZip 8.1 on Windows XP SP2. It is caused by a crafted command line which is used to launch a local cmd.exe. The exploit is coded by ATmaCA and was tested with WinZip 8.1 on Win XP Sp2 En. The bug was fixed on WinZip 9.0 Service Release 1 (SR-1).
Mitigation:
Upgrade to WinZip 9.0 Service Release 1 (SR-1)