CVE-2025-33028 is a Mark-of-the-Web Bypass Vulnerability in WinZip through version 29.0, stemming from an incomplete fix for a previous vulnerability. This flaw allows attackers to bypass security warnings by preventing the Mark-of-the-Web from propagating to extracted files from a crafted archive, potentially leading to arbitrary code execution with user interaction. Rated Medium severity (CVSS 6.1), it requires user interaction, such as visiting a malicious page or opening a malicious file, to exploit. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and its validity is disputed by a third party.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 29.0CPE match | cpe:2.3:a:winzip:winzip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.