VulnerabilityModified
CVE-2006-5198
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."
MEDIUM 4.0EPSS 60.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 60.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
- EPSS
- 60.44% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- winzip/winzip
- Source
- cve@mitre.org
References
- http://isc.sans.org/diary.php?storyid=1861
- http://secunia.com/advisories/22891
- http://securitytracker.com/id?1017226
- http://www.kb.cert.org/vuls/id/512804US Government Resource
- http://www.securityfocus.com/archive/1/451589/100/0/threaded
- http://www.securityfocus.com/bid/21060
- http://www.vupen.com/english/advisories/2006/4509
- http://www.winzip.com/wz7245.htm
- http://www.zerodayinitiative.com/advisories/ZDI-06-040.htmlVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067
- http://isc.sans.org/diary.php?storyid=1861
- http://secunia.com/advisories/22891
- http://securitytracker.com/id?1017226
- http://www.kb.cert.org/vuls/id/512804US Government Resource
- http://www.securityfocus.com/archive/1/451589/100/0/threaded
- http://www.securityfocus.com/bid/21060
- http://www.vupen.com/english/advisories/2006/4509
- http://www.winzip.com/wz7245.htm
- http://www.zerodayinitiative.com/advisories/ZDI-06-040.htmlVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.