Impact
The vulnerability in BandiZip 7.37 allows attackers to bypass the Mark‑of‑the‑Web protection mechanism that normally flags files downloaded from the internet, preventing accidental execution. Based on the description, the flaw is a failure to enforce correct authentication or control mechanisms, classified as CWE‑693. Bypassing this protection can lead to unintended code execution under the user’s privileges when malicious archives are opened.
Affected Systems
Only the 7.37 release of BandiZip is explicitly listed as affected. The advisory does not mention other versions or related products. Based on the available data, systems running this specific version may be at risk, whereas earlier or later releases are not confirmed to contain the flaw.
Risk and Exploitability
The likely attack vector, inferred from the description, is a remote attacker delivering a crafted archive that, when opened with BandiZip, bypasses the Mark‑of‑the‑Web check. The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1% suggests low likelihood of exploitation at present. The vulnerability is not in the CISA KEV catalog, so there is no known widespread exploitation. The bypass does not require local privileged access and can be triggered by any user who can place files in the extraction path, making the risk spread to all users of that installation.
OpenCVE Enrichment