Lucene search

K
cve[email protected]CVE-2008-3442
HistoryOct 03, 2022 - 4:13 p.m.

CVE-2008-3442

2022-10-0316:13:41
CWE-94
web.nvd.nist.gov
22
cve-2008-3442
winzip
update authentication
vulnerability
evilgrade
dns cache poisoning
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.0%

WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Affected configurations

NVD
Node
winzipwinzipMatch7.0
OR
winzipwinzipMatch8.0
OR
winzipwinzipMatch8.1
OR
winzipwinzipMatch8.1sr1
OR
winzipwinzipMatch9.0
OR
winzipwinzipMatch9.0sr1
OR
winzipwinzipMatch10.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.0%

Related for CVE-2008-3442