WinZip FileView ActiveX controls CreateNewFolderFromName Method Buffer Overflow Vulnerability ------------------------------------------------------------------ SUMMARY: A vulnerability has been identified in Winzip 10.0 Build 6667,May be other version, which could be exploited by remote or local attackers to execute arbitrary commands. The first flaw is due to errors in the "WZFILEVIEW.FileViewCtrl.61" ActiveX control that does not validate input passed to CreateNewFolderFromName methods. ---------- DETAILS: Vulnerable systems: Winzip 10.0 Build 6667 and probable others Exploit: ------------------------------------------ Xiao Hui Team:NCNIPC HomePage:www.nipc.org.cn