In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, Bandizip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 25 Aug 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:bandisoft:bandizip:*:*:*:*:*:*:*:* cpe:2.3:a:bandisoft:bandizip:*:*:*:*:*:windows:*:*

Fri, 25 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Bandisoft
Bandisoft bandizip
Weaknesses CWE-829
CPEs cpe:2.3:a:bandisoft:bandizip:*:*:*:*:*:*:*:*
Vendors & Products Bandisoft
Bandisoft bandizip

Tue, 15 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-830
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
Description In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, Bandizip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-15T17:51:05.694Z

Reserved: 2025-04-15T00:00:00.000Z

Link: CVE-2025-33027

cve-icon Vulnrichment

Updated: 2025-04-15T17:51:00.530Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-15T18:15:53.183

Modified: 2025-08-25T02:24:21.053

Link: CVE-2025-33027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.