CVE-2008-3442
WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to exe
WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
HIGH · CVSS 7.5
EPSS 0.00758
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0