Security News > 2020 > December > Hackers can use WinZip insecure server connection to drop malware

Hackers can use WinZip insecure server connection to drop malware
2020-12-10 09:47

The server-client communication in certain versions of the WinZip file compression tool is insecure and could be modified to serve malware or fraudulent content to users.

WinZip has been a long-standing utility for Windows users with file archiving needs beyond the support built in the operating system.

WinZip is currently at version 25 but earlier releases check the server for updates over an unencrypted connection, a weakness that could be exploited by a malicious actor.

Given the insecure nature of the communication channel, Rakhmanov says that the traffic can be "Grabbed, manipulated, or hijacked" by an attacker on the same network as the WinZip user.

This will stop the client from querying the WinZip server for the availability of a new version.


News URL

https://www.bleepingcomputer.com/news/security/hackers-can-use-winzip-insecure-server-connection-to-drop-malware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Winzip 1 1 4 2 4 11