Junglewise Threat Intelligence

CVE-2025-50329: ConeXware PowerArchiver Mark-of-the-Web bypass in powerarc.exe

CVE-2025-50329 · Severity: info · CVSS 7.8 · Published 2026-07-22

Executive brief

PowerArchiver is a file compression and encryption utility used to manage archives like ZIP and RAR files. A security vulnerability exists where the software fails to apply 'Mark-of-the-Web' security warnings to files extracted from downloaded archives. This could allow an attacker to trick a user into running a malicious file that bypasses standard Windows security prompts, potentially leading to unauthorized code execution on the user's computer.

Technical details

A Protection Mechanism Failure (CWE-693) exists in ConeXware PowerArchiver versions up to 22.00.11. When the application extracts files from an archive that possesses the 'Mark-of-the-Web' (MotW) NTFS zone identifier, it fails to propagate this attribute to the resulting extracted files. An attacker can exploit this by delivering a malicious executable within an archive; once extracted, the file will not trigger the standard Windows SmartScreen or security warnings when launched. This allows for arbitrary code execution in the context of the current user, provided the user is enticed to extract and run the malicious payload. The vulnerability is reportedly addressed in versions later than 22.00.11.

Affected products

  • ConeXware PowerArchiver up to 22.00.11

Timeline

  • 2026-07-22: disclosed: NVD Published Date

References