// For flags

CVE-2006-5198

WinZip FileView ActiveX Control Unsafe Method Exposure Vulnerability

Severity Score

4.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."

El control ActiveX WZFILEVIEW.FileViewCtrl.61 (también conocido como control ActiveX Sky Software "FileView") para WinZip 10.0 anterior al build 7245 permite a atacantes remotos ejecutar código de su elección mediante "métodos no seguros" no especificados.

This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The specific flaw exists within the ActiveX control WZFILEVIEW.FileViewCtrl.61, CLSID:
A09AE68F-B14D-43ED-B713-BA413F034904
A re-branded version of the "FileView" ActiveX control developed by Sky Software. The object is marked "Safe for Scripting" and exposes several unsafe methods which can be leveraged to result in arbitrary code execution with no further interaction.

*Credits: Anonymous
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-10-09 CVE Reserved
  • 2006-11-14 CVE Published
  • 2010-04-30 First Exploit
  • 2024-05-26 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Winzip
Search vendor "Winzip"
Winzip
Search vendor "Winzip" for product "Winzip"
10.0
Search vendor "Winzip" for product "Winzip" and version "10.0"
-
Affected