CVE-2025-46652
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 830
Summary
CVE-2025-46652: IZArc versions up to 4.5 contain a Mark-of-the-Web Bypass vulnerability. During archive file extractions, the Mark-of-the-Web attribute is not propagated to extracted files, potentially allowing malicious files with this attribute to bypass security checks and execute unintended code. This could lead to serious security implications if a user opens a maliciously crafted archive file. It is crucial for users to upgrade to the latest version of IZArc or employ alternative archive management tools to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Izarc
Affected Vendors
- IZArc