CVE-2025-33026

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 22, 2025
CWE ID 829
CWE ID 830

Summary

CVE-2025-33026 is a vulnerability affecting PeaZip versions up to 10.4.0. This issue involves a Mark-of-the-Web (MotW) bypass, allowing attackers to bypass MotW protection when extracting files from a maliciously crafted archive. user interaction is necessary for exploitation, as the target must visit a malicious webpage or open a malicious file. The vulnerability lies in PeaZip's handling of archived files, as it fails to propagate the MotW to extracted files. As a result, attackers can execute arbitrary code in the context of the current user.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share