Cyber Resilience

CVE-2025-33026

Peazip ≤ 10.4.0

Published
15 April 2025
Modified
24 October 2025
Patch / advisory
CVSS Score v3.1 6.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score 0.0027 19th percentile
Risk Priority 45 floored blend · peak EPSS

Summary

CVE-2025-33026 is a medium-severity Inclusion of Web Functionality from an Untrusted Source (CWE-830) vulnerability in Peazip Peazip. Its CVSS base score is 6.1 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Supply Chain Compromise (T1195); ranked at the 19th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SC-18 (Mobile Code) and SR-4 (Provenance) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerability in that the target must visit a…

more

malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, PeaZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1195 Supply Chain Compromise Initial Access
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
T1176 Software Extensions Persistence
Adversaries may abuse software extensions to establish persistent access to victim systems.
T1195.001 Compromise Software Dependencies and Development Tools Initial Access
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
T1195.002 Compromise Software Supply Chain Initial Access
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
T1505.004 IIS Components Persistence
Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence.
T1505.005 Terminal Services DLL Persistence
Adversaries may abuse components of Terminal Services to enable persistent access to systems.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-6891Same product: Peazip Peazip
CVE-2025-33027Shared CWE-829, CWE-830
CVE-2026-47172Shared CWE-829
CVE-2024-31144Shared CWE-829
CVE-2026-6357Shared CWE-829
CVE-2023-33559Shared CWE-829
CVE-2024-48336Shared CWE-829
CVE-2024-45482Shared CWE-829
CVE-2026-1699Shared CWE-829
CVE-2026-54325Shared CWE-829

Affected Assets

peazip
peazip
≤ 10.4.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 6 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V14.2.3
  • V3.5.6
  • V9.1.3
  • V15.3.2

Mitigating Controls (NIST 800-53 r5) AI

Defines acceptable mobile/active code and authorizes/monitors its use, directly blocking inclusion of untrusted web scripts or widgets.

Requires documented, valid provenance for components, preventing acceptance of code from outside the trusted sphere.

Configures the system to permit only essential functionality, thereby restricting the ability to embed arbitrary external web code.

Requires external service providers to meet the organization's security and privacy requirements before their functionality (e.g., widgets) may be integrated.

Implements detection and prevention of counterfeit or inauthentic components before they are integrated.

Establishes processes to identify and remediate supply-chain weaknesses that would allow untrusted external web components to be incorporated.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

ID.RA-09 full match
prevents

Pre-acquisition integrity/authenticity checks directly prevent inclusion of untrusted code.

GV.SC-01 mostly match
prevents

Supply-chain program directly governs inclusion of third-party executable code.

GV.SC-05 mostly match
prevents

Contractual requirements can mandate vetting of web sources and prohibit untrusted inclusions.

GV.SC-06 mostly match
prevents

Due diligence before supplier relationships directly prevents inclusion of untrusted web functionality.

GV.SC-07 mostly match
prevents

Assessing supplier risks and products reduces the chance of embedding untrusted web widgets or scripts.

ID.RA-10 mostly match
prevents

Supplier assessments prior to acquisition address the root risk of untrusted web sources.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

By requiring suppliers to propagate security requirements and to disclose component provenance, the control limits the inclusion of functionality obtained from untrusted third-party sources without oversight.

prevents

Secure architecture principles discourage embedding untrusted content, yet require additional controls for full mitigation.

finds

Security testing can detect the weakness, but does not prevent its introduction during design or coding.

degrades

Network security controls can restrict or block untrusted external web content, but do not specifically address inclusion of web widgets.

degrades

Web filtering can prevent loading of untrusted web functionality, directly mitigating the weakness.

prevents

Application security requirements can mandate vetting of external web components, but do not guarantee technical enforcement.

Hardening callouts derived

Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).

Oracle Linux 8 (1 rule)
  • V-248635 Executable search paths within the initialization files of all local interactive OL 8 users must only contain paths that resolve to the system default or the user's home directory. prevents CWE-829
Oracle Linux 9 (1 rule)
  • V-271847 OL 9 must be configured so that executable search paths within the initialization files of all local interactive users must only contain paths that resolve to the system default or the users home directory. prevents CWE-829
RHEL 7 (1 rule)
  • V-204477 The Red Hat Enterprise Linux operating system must be configured so that all local interactive user initialization files executable search paths contain only paths that resolve to the users home directory. prevents CWE-829
RHEL 8 (1 rule)
  • V-230317 Executable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory. prevents CWE-829
RHEL 9 (1 rule)
  • V-258050 Executable search paths within the initialization files of all local interactive RHEL 9 users must only contain paths that resolve to the system default or the users home directory. prevents CWE-829
Windows 10 (1 rule)
  • V-220737 Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email. prevents CWE-829

References