Mark-of-the-Web Bypass Vulnerability in PeaZip Software
CVE-2025-33026

6.1MEDIUM

Key Information:

Vendor

Peazip

Status
Vendor
CVE Published:
15 April 2025

What is CVE-2025-33026?

In PeaZip versions up to 10.4.0, a vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism. This is executed when users are tricked into extracting files from malicious archives. The flaw specifically lies in the improper handling of archived files, which causes extracted files to not inherit the Web protection flag. As a result, attackers can exploit this issue to execute arbitrary code in the context of the user, compromising system integrity.

Affected Version(s)

PeaZip 0 <= 10.4.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.