Some vulnerabilities have been reported in WinZip, which can be exploited by malicious people to compromise a user's system.
1) Several unspecified insecure methods exist in the FileView ActiveX control (WZFILEVIEW.FileViewCtrl.61). This can be exploited to execute arbitrary code when a user e.g. visits a malicious website.
2) A boundary error in the FileView ActiveX control within the handling of the "filepattern" property can be exploited to cause a buffer overflow.
The vulnerabilities are reported in WinZip 10.0 versions prior to Build 7245.
Secunia Security


Reply With Quote