A significant vulnerability has been identified in WinZip, a widely used file archiving application, potentially enabling attackers to bypass critical security mechanisms and execute malicious code on targeted systems. Designated as CVE-2024-8811 and assigned a CVSS score of 7.8 (High), the flaw impacts all WinZip versions earlier than 76.8. The issue arises from improper handling of the Mark-of-the-Web (MOTW), a Windows security feature that labels files downloaded from the internet as potentially dangerous. This label prompts Windows to apply enhanced security measures when such files are accessed. Researchers from Trend Micro's Zero Day Initiative, led by Peter Girnus, discovered that WinZip strips away the MOTW flag when processing downloaded archives. As a result, even if a file contains malicious content and originates from the internet, WinZip removes the MOTW warning, potentially deceiving users into thinking the file is safe. The attack works by tricking users into downloading a ZIP archive containing malicious files. When opened with WinZip, the software removes the MOTW flag, and Windows fails to enforce security measures. This enables the malicious code to execute when the user extracts the files. The consequences of exploiting this vulnerability are severe. Attackers could deliver malware, such as ransomware or spyware, and compromise user systems. Sensitive data may be stolen, or attackers could gain control of the system for further attacks. Users are urged to update to WinZip version 76.8 or later to address this vulnerability and preserve the MOTW flag, ensuring continued protection against malicious files downloaded from the internet.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...