CVE-2025-50330

ZipGenius Team · ZipGenius

A privilege escalation and remote code execution vulnerability exists in ZipGenius v6.3.2.3116 and earlier due to an issue within the zipgenius.exe binary.

Executive summary

A critical privilege escalation and arbitrary code execution flaw in ZipGenius allows remote attackers to execute code with elevated permissions via malicious archives.

Vulnerability

This is a privilege escalation and arbitrary code execution vulnerability triggered through the zipgenius.exe binary. An unauthenticated remote attacker can exploit this by delivering a crafted archive to a user or by triggering the vulnerable path during standard file processing workflows.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it allows an attacker to execute arbitrary code with elevated privileges on the host system. Given the CVSS score of 8.8, this vulnerability is classified as high severity, potentially leading to full system compromise, data theft, and unauthorized lateral movement within the network.

Remediation

Immediate Action: Users should restrict the use of ZipGenius until an official patch is released by the vendor. Monitor the vendor advisory URL for the release of a version that addresses this vulnerability.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious execution patterns originating from zipgenius.exe, particularly when interacting with untrusted or externally sourced archive files.

Compensating Controls: Deploy endpoint protection solutions to detect and block the execution of unauthorized processes spawned by archive utilities. Ensure that users are instructed not to open archive files from untrusted or unknown sources.

Exploitation status

Public Exploit Available: No (no confirmed public exploit available).

Analyst recommendation

Given the potential for complete system compromise, organizations should treat this vulnerability with extreme urgency. Immediately implement restrictions on the use of the affected software and ensure that security monitoring tools are configured to alert on anomalous activity linked to the application.