vendor:
ZIP Password Recovery
by:
ZwX
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: ZIP Password Recovery
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2020
ZIP Password Recovery 2.30 – ‘ZIP File’ Denial of Service (PoC)
The vulnerability allows an attacker to cause a denial of service (DoS) condition by providing specially crafted input to the ZIP Password Recovery software. By creating a file with specific characters and pasting them into the 'Select Your ZIP File' field, the software crashes.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to avoid using the affected software or to use alternative software for ZIP file password recovery.