Impact
The flaw in ZipGenius Team’s ZIPGenius v6.3.2.3116 and earlier releases resides in the zipgenius.exe component. It allows a remote attacker to elevate privileges and execute arbitrary code by exploiting improper handling of privileged operations (CWE‑693). By achieving elevated system privileges, an attacker can gain full control over the host, compromising confidentiality, integrity, and availability.
Affected Systems
ZipGenius Team’s ZIPGenius v6.3.2.3116 and all earlier releases contain the vulnerable zipgenius.exe. No other vendors or products have been reported as affected.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity, while the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote via a malicious ZIP file that triggers zipgenius.exe to process it, allowing the attacker to gain elevated privileges and run arbitrary code on the target system. The exploitation requires that the victim launches the application or otherwise processes the crafted ZIP file.
OpenCVE Enrichment