CVE-2024-8811
WinZip vulnerability analysis and mitigation

Overview

The WinZip Mark-of-the-Web Bypass Vulnerability (CVE-2024-8811) is a critical security flaw discovered in WinZip file archiving software. The vulnerability was identified on May 3, 2024, and publicly disclosed on September 17, 2024. This security issue affects all versions of WinZip prior to version 76.8 for subscription users and version 29.0 for perpetual license holders. The vulnerability has been assigned a CVSS score of 7.8 (High), indicating its significant security impact (NVD, ZDI Advisory).

Technical details

The vulnerability exists within WinZip's handling of archive files and specifically affects the Mark-of-the-Web (MotW) protection mechanism. When a user opens an archive file that contains the MotW security tag, WinZip incorrectly removes this tag from both the archive file and any subsequently extracted files. The MotW is a crucial Windows security feature that flags files downloaded from the internet as potentially unsafe. The vulnerability was discovered by Peter Girnus (@gothburz) of Trend Micro Zero Day Initiative and was assigned the tracking number ZDI-CAN-23983 (ZDI Advisory).

Impact

The exploitation of this vulnerability could lead to severe consequences, including the execution of arbitrary code in the context of the current user. By bypassing the Mark-of-the-Web protection, malicious files could evade Windows security measures designed to protect users from untrusted sources. This could potentially allow attackers to deliver and execute malware, steal sensitive information, or gain control of the affected system (Security Online).

Mitigation and workarounds

Users of affected WinZip versions are strongly advised to update their software immediately. For subscription users, the vulnerability has been patched in version 76.8 and later, while perpetual license holders should update to version 29.0 or later. These updates address the vulnerability by ensuring the Mark-of-the-Web is properly preserved (ASEC, ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management