CVE-2004-0333

UUDeview <8.1 - Remote Code Execution

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0333. PoCs published by snooq.

AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2004-0333, targeting a heap overflow vulnerability in WinZip 8.1's MIME parsing. It manipulates the EBX register to divert execution flow into shellcode, spawning 'notepad.exe' as a harmless payload.

Description

Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by snooq · clocalwindows
https://www.exploit-db.com/exploits/272

This is a proof-of-concept exploit for CVE-2004-0333, targeting a heap overflow vulnerability in WinZip 8.1's MIME parsing. It manipulates the EBX register to divert execution flow into shellcode, spawning 'notepad.exe' as a harmless payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WinZip 8.1
No auth needed
Prerequisites: WinZip 8.1 installed · WinZip must be running before opening the exploit file · Target system must be Windows XP SP1 or Windows 2000 SP1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Various Sources x_refsource_confirm
http://www.winzip.com/fmwz90.htm
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15490
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/4119
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9758
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/10995
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-092.shtml
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/116182
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15336
Various Sources third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=76&type=vulnerabiliti&flashstatus=true
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11019

Scores

EPSS 0.2423
EPSS Percentile 97.6%

Details

Status published
Products (7)
gentoo/linux 1.4 (4 CPE variants)
openpkg/openpkg
uudeview/uudeview 0.5.18
uudeview/uudeview 0.5.19
winzip/winzip 7.0
winzip/winzip 8.0
winzip/winzip 8.1 (2 CPE variants)
Published Nov 23, 2004
Tracked Since Feb 18, 2026