CVE Feed

    Dashboard / CVE / CVE-2014-2720

    CVE-2014-2720

    IZArc 4.1.8 displays a file's name on the basis of a ZIP archive's Central Directory entry, but launches this file on the basis of a ZIP archive's local file header, which allows user-assisted remote attackers to conduct file-extension spoofing attacks via a modified Central Directory, as demonstrated by unintended code execution prompted by a .jpg extension in the Central Directory and a .exe extension in the local file header.

    Published:May 27, 2014
    Last Modified:Apr 12, 2025
    EPS:May 27, 2014
    EPSS Score:0.02005
    CVSS Score:6.8

    Affected Products

    Vendor
    Izarc
    Product
    Izarc

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High