CVE-2004-1465

WinZip 9.0 - Buffer Overflow via Command Line

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1465. PoCs published by ATmaCA.

AI-analyzed exploit summary This exploit leverages a local buffer overflow in WinZip 8.1 via a crafted .tmp file and command-line arguments to execute arbitrary shellcode, launching cmd.exe. The shellcode is hardcoded with a WinXP SP2-specific address for system() and a JMP ESP instruction.

Description

Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ATmaCA · c++localwindows
https://www.exploit-db.com/exploits/1034

This exploit leverages a local buffer overflow in WinZip 8.1 via a crafted .tmp file and command-line arguments to execute arbitrary shellcode, launching cmd.exe. The shellcode is hardcoded with a WinXP SP2-specific address for system() and a JMP ESP instruction.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WinZip 8.1
No auth needed
Prerequisites: WinZip 8.1 installed · Local access to the target system · WinXP SP2 environment for reliable execution
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109416099301369&w=2
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11092
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17192
Patch x_refsource_confirm
http://www.winzip.com/wz90sr1.htm
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1011132
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17197
Vendor Advisory third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-211.shtml

Scores

EPSS 0.0254
EPSS Percentile 85.8%

Details

Status published
Products (4)
winzip/winzip 7.0
winzip/winzip 8.0
winzip/winzip 8.1 (2 CPE variants)
winzip/winzip 9.0
Published Dec 31, 2004
Tracked Since Feb 18, 2026