vendor:
ZipX for Windows
by:
C4SS!0 G0M3S
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: ZipX for Windows
Affected Version From: v1.71
Affected Version To: v1.71
Patch Exists: NO
Related CWE:
CPE: a:zipx:zipx:1.71
Platforms Tested: Windows XP SP3 Brazilian Portuguese
2011
ZipX for Windows v1.71 ZIP File Buffer Overflow Exploit
The exploit takes advantage of a buffer overflow vulnerability in the ZipX for Windows v1.71 software. By creating a specially crafted ZIP file, an attacker can trigger the buffer overflow and execute arbitrary code on the target system. The exploit has been tested on Windows XP SP3 Brazilian Portuguese.
Mitigation:
Update to a patched version of the software. Avoid opening ZIP files from untrusted sources.