Skip to main content

WinZipGDI+ Library Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 2 Oct 2008 4865 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in WinZip, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused due to the application placing a vulnerable "gdiplus.dll" library in the program folder and using it on Windows 2000 systems, which could be exploited to execute arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • WinZip version 11.0
  • WinZip version 11.1
  • WinZip version 11.2

Solutions

Before installation of the software, please visit the software manufacturerweb-site for more details.

Upgrade to WinZip version 11.2 SR-1 :
http://download.winzip.com/nrb/winzip112.exe


Vulnerability Identifier


Source


Related Link