CVE-2025-33026
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 15, 2025
Updated: Apr 22, 2025
CWE ID 829
CWE ID 830
Summary
CVE-2025-33026 is a vulnerability affecting PeaZip versions up to 10.4.0. This issue involves a Mark-of-the-Web (MotW) bypass, allowing attackers to bypass MotW protection when extracting files from a maliciously crafted archive. user interaction is necessary for exploitation, as the target must visit a malicious webpage or open a malicious file. The vulnerability lies in PeaZip's handling of archived files, as it fails to propagate the MotW to extracted files. As a result, attackers can execute arbitrary code in the context of the current user.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PeaZip
Affected Vendors
- Peazip