CVE-2025-33028 Details
Description
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, WinZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: a third party has reported that this is a false positive, and has observed that the original CVE-2025-33028.md file has been deleted on GitHub. Also, this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.
A Mark-of-the-Web bypass vulnerability has been identified in WinZip versions through 29.0. This issue arises from an incomplete fix for a previous vulnerability, CVE-2024-8811. The flaw allows attackers to circumvent the Mark-of-the-Web protection when extracting files from a crafted archive that includes this mark. WinZip fails to transfer the Mark-of-the-Web to the extracted files, enabling the execution of arbitrary code in the context of the current user. Exploitation requires user interaction, such as visiting a malicious page or opening a harmful file.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 15, 2025CISA-ADP
Assessed Apr 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-830 | Inclusion of Web Functionality from an Untrusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Alludo WinZip | <= 29.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | CVE Modified | [email protected] |
| Aug 4, 2025 | CVE Modified | [email protected] |
| May 6, 2025 | CVE Modified | [email protected] |
| Apr 15, 2025 | New CVE Received | [email protected] |
Volerion