Junglewise Threat Intelligence

CVE-2025-50324: Milos Paripovic OneCommander Mark-of-the-Web bypass

CVE-2025-50324 · Severity: info · CVSS 7.8 · Published 2026-07-22

Executive brief

OneCommander, a file management application for Windows, contains a security flaw in how it handles downloaded files. When a user extracts files from a compressed archive (like a ZIP file) downloaded from the internet, the software fails to apply the standard Windows 'Mark-of-the-Web' security warning to the new files. This could allow a malicious file to run without the usual security prompts, potentially leading to a full system compromise if a user is tricked into opening a malicious archive.

Technical details

A Protection Mechanism Failure (CWE-693) exists in OneCommander v3.96.0.0 and earlier. When the application extracts files from an archive that possesses the 'Mark-of-the-Web' (MotW) NTFS alternate data stream, it fails to propagate this zone identifier to the extracted output files. An attacker can exploit this by delivering a malicious executable within a compressed archive; because the extracted file lacks the MotW, Windows SmartScreen and other security features may not trigger the expected 'Unknown Publisher' or 'Downloaded from the Internet' warnings. Successful exploitation requires a user to download the archive and manually execute the extracted file, resulting in arbitrary code execution in the context of the current user.

Affected products

  • Milos Paripovic OneCommander 3.96.0.0 and earlier

Timeline

  • 2026-07-22: advisory: CVE-2025-50324 published by NVD/MITRE
  • 2026-03-06: patched: Version 3.108.0.0 released (based on vendor site download date)

References