CVE-2018-16518: Primx Zed!

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.

Affected products

  • Primx Zed!: up to and including 6.1
  • Primx Zed! Free: up to and including 1.0

Published 2018-09-05. Last modified 2026-06-17.