WinZip Security Update Advisory (CVE-2024-8811)

Overview

An update has been released to address vulnerabilities in WinZip. Users of the affected versions are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-8811

  • All versions prior to WinZip 76.8

     

Resolved Vulnerabilities

 

Mark-of-the-Web Bypass Vulnerability (CVE-2024-8811) When a user accesses a malicious file or webpage, security tags are removed, allowing arbitrary code execution

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-8811

  • WinZip version 76.8

     

Referenced Sites

 

[1] CVE-2024-8811 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-8811

[2] WinZip Mark-of-the-Web Bypass Vulnerability

https://www.zerodayinitiative.com/advisories/ZDI-24-1234/