Impact
The flaw in Franco Corbelli's ZPAQFRANZ version 61.3 and earlier enables a remote attacker to bypass the Mark‑of‑the‑Web protection and execute arbitrary code with elevated privileges, meeting the criteria for privilege escalation and remote code execution. The weakness involves insufficient validation of security attributes, as indicated by CWE‑1289 and CWE‑693, and permits the application to trust manipulated input for code execution.
Affected Systems
The vulnerability affects Franco Corbelli's ZPAQFRANZ software, specifically version 61.3 and all earlier releases. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 classifies this as high severity. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is low. The vulnerability is not currently listed in the CISA KEV catalog. A likely attack vector is remote: an attacker must supply a crafted file or payload that the software will process, thereby circumventing Mark‑of‑the‑Web checks and executing arbitrary code with elevated rights.
OpenCVE Enrichment