Executive brief
ZPAQFRANZ is a specialized data compression and backup utility. A security flaw in versions 61.3 and earlier allows malicious files to bypass Windows security warnings (Mark-of-the-Web) when they are extracted from an archive. If a user is tricked into downloading and extracting a malicious archive, they could unknowingly run harmful code that could compromise their computer or data.
Technical details
A Protection Mechanism Failure (CWE-693) exists in ZPAQFRANZ up to version 61.3. When the utility extracts files from an archive that has been tagged with the 'Mark-of-the-Web' (MotW) attribute (indicating it was downloaded from the internet), it fails to propagate this security zone information to the resulting extracted files. An attacker can exploit this by providing a malicious archive; once extracted, the operating system will not trigger the standard security warnings or SmartScreen protections when the user attempts to run the extracted files. This allows for arbitrary code execution in the context of the current user, provided they can be induced to download and extract the archive.
Affected products
- Franco Corbelli ZPAQFRANZ 61.3 and earlier
Timeline
- 2026-07-22: disclosed: Initial CVE publication date