PeaZip Compressed Filename Command Injection (CVE-2009-2261)

A command injection vulnerability exists in PeaZip. A remote attacker may exploit this vulnerability by sending a specially crafted Zip file to a target user, and convince him to open this file with PeaZip. Successful exploitation would allow an attacker to execute commands in the security context of the logged on user.

from Check Point Update Services Advisories http://ift.tt/2BEqSNa

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...