CVE-2014-1680: Bandisoft Bandizip

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Untrusted search path vulnerability in Bandisoft Bandizip before 3.10 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory.

Affected products

  • Bandisoft Bandizip: up to and including 3.09; version 3.00 only; version 3.01 only; version 3.02 only; version 3.03 only; version 3.04 only; …

Published 2014-02-14. Last modified 2026-06-17.