Vulnerability record · CVE-2006-5198 · published 14 November 2006
CVE-2006-5198: WinZip FileView ActiveX control unsafe methods allow remote code execution
Winzip · Winzip
The WZFILEVIEW.FileViewCtrl.61 ActiveX control shipped with WinZip 10.0 before build 7245 exposes unsafe methods that let a remote attacker run arbitrary code. The flaw is in the ActiveX control, not the archiver itself, so any host with the vulnerable control registered is exposed. It matters because code execution in the browser or mail client context can lead to full system compromise.
Description
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."
AV:N/AC:H/Au:N/C:P/I:P/A:N
Automated analysis
high priorityRemote unauthenticated code execution with a very high EPSS score, though the CVSS 2.0 base score is only 4.0 and no KEV listing exists.
What it is
The WZFILEVIEW.FileViewCtrl.61 ActiveX control shipped with WinZip 10.0 before build 7245 exposes unsafe methods that let a remote attacker run arbitrary code. The flaw is in the ActiveX control, not the archiver itself, so any host with the vulnerable control registered is exposed. It matters because code execution in the browser or mail client context can lead to full system compromise.
Impact
An attacker who can get the control instantiated gains arbitrary code execution with the privileges of the logged-on user. That enables malware installation, data theft, or further lateral movement from the victim host.
Attack surface
Reached over the network via a web page or HTML email that instantiates the ActiveX control; the CVSS vector AV:N/Au:N indicates no authentication is required, and the user must load the malicious content in a browser or client that renders the control.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.60439 (99.1st percentile), indicating a high modeled likelihood of exploitation; references include a vendor advisory and a Zero Day Initiative advisory, though no public exploit tag is present.
What to do
- Upgrade WinZip to build 7245 or later, which removes or fixes the vulnerable control.
- Apply Microsoft security bulletin MS06-067, which addresses the affected ActiveX control.
- Set the kill bit for the WZFILEVIEW.FileViewCtrl.61 CLSID to block instantiation in Internet Explorer.
- Restrict ActiveX execution in browsers and email clients, and avoid opening untrusted HTML content on hosts with WinZip 10.0 installed.
Detection
- Search endpoints for the WZFILEVIEW.FileViewCtrl.61 CLSID in the registry to find hosts with the vulnerable control registered.
- Monitor browser and email client processes for unexpected child processes or script execution following ActiveX instantiation.
- Review proxy and IDS logs for pages or emails referencing the FileView control or known exploit hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5198 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5198), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.