Description
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
Published: 2026-07-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in ZipGenius Team’s ZIPGenius v6.3.2.3116 and earlier releases resides in the zipgenius.exe component. It allows a remote attacker to elevate privileges and execute arbitrary code by exploiting improper handling of privileged operations (CWE‑693). By achieving elevated system privileges, an attacker can gain full control over the host, compromising confidentiality, integrity, and availability.

Affected Systems

ZipGenius Team’s ZIPGenius v6.3.2.3116 and all earlier releases contain the vulnerable zipgenius.exe. No other vendors or products have been reported as affected.

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as high severity, while the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote via a malicious ZIP file that triggers zipgenius.exe to process it, allowing the attacker to gain elevated privileges and run arbitrary code on the target system. The exploitation requires that the victim launches the application or otherwise processes the crafted ZIP file.

Generated by OpenCVE AI on August 4, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to a version that removes the vulnerability.
  • If no patch is yet available, uninstall or disable zipgenius.exe to stop the vulnerable component from executing.
  • Configure AppLocker or Software Restriction Policies to block zipgenius.exe until a fix is released.
  • Monitor the system for unexpected elevation of privileges or execution of zipgenius.exe from untrusted sources.

Generated by OpenCVE AI on August 4, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via zipgenius.exe in ZipGenius Team Application

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via zipgenius.exe in ZipGenius Team Application

Mon, 27 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Arbitrary Code Execution in ZipGenius Team ZipGenius
Weaknesses CWE-269
CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Arbitrary Code Execution in ZipGenius Team ZipGenius
Weaknesses CWE-269
CWE-284

Thu, 23 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Zipgenius
Zipgenius zipgenius
Vendors & Products Zipgenius
Zipgenius zipgenius

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
References

Subscriptions

Zipgenius Zipgenius
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:11:13.648Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50330

cve-icon Vulnrichment

Updated: 2026-07-24T19:10:36.888Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:17:11.983

Modified: 2026-07-24T20:17:01.963

Link: CVE-2025-50330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure