External risk intelligence

Power Archiver Privilege Escalation and Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-50329

Power Archiver is a desktop file compression utility. It is a client-side application typically installed on local workstations or personal computers. It is not designed to be an internet-facing service, web application, or edge gateway, and does not possess a listening network port that would make it reachable from the public internet in common real-world deployments.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability found in ConeXware, Inc.'s Power Archiver software. The issue could allow unauthorized remote access to escalate privileges and execute arbitrary code, posing a significant security risk if exploited. Given the nature of the affected software as a desktop utility, the primary concern is to confirm if this product is in use within the organization and, if so, understand the potential exposure.

  • Software vulnerability allows remote code execution.
  • Confirms if our systems are exposed.
  • Understand product usage and potential risks.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted file to a user. When the user opens this file using a vulnerable version of Power Archiver, it could lead to the execution of arbitrary code and privilege escalation on the user's machine.

  • No special access needed.
  • Opening a crafted file.
  • Privilege escalation and code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to gain elevated privileges and execute arbitrary code on a system running the affected software. This could occur when a user opens a specially crafted archive file. The potential impact is a compromise of the affected system.

  • System data and code execution at risk.
  • Via specially crafted archive files.
  • Full system compromise is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides in a desktop file compression utility, ConeXware, Inc Power Archiver. Given its nature as a client-side application, ownership likely falls to endpoint or workstation management teams responsible for user-installed software. The immediate first step is to identify all systems with the affected software, assess its reachability and criticality in the environment, and then coordinate with accountable owners for remediation planning.

  • Endpoint management owns the issue.
  • Verify software installation and reachability.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ConeXware Power Archiver?

Power Archiver is a desktop utility used for file compression and archiving. Like other tools in this category, it is designed to run locally on workstations to manage, zip, and extract various file formats. It is a client-side application rather than a server-based service, meaning it typically resides on personal computers or enterprise endpoints where users manage their own files.

How does CVE-2025-50329 cause a security weakness?

This vulnerability is classified as CWE-693, which relates to protection mechanism failures. In plain terms, the software fails to properly secure its internal processes when handling archive files. This flaw allows a malicious actor to bypass standard security controls, granting them the ability to execute unauthorized commands or gain higher levels of control over the affected computer system.

Do I need to be logged into a network for this to trigger?

The vulnerability is triggered specifically when a user opens a specially crafted archive file. It does not require an attacker to have prior network access or special credentials. Importantly, the bug is not triggered by simply having the software installed; the malicious code only executes when the user interacts with a deceptive file provided by an attacker.

Is my system at risk if it isn't internet-facing?

According to Halo Surface Signal, Power Archiver is a desktop application and is not designed to be an internet-facing service. Because it lacks a listening network port, it is not directly reachable from the public internet in standard configurations. However, the risk remains if a user is tricked into opening a malicious file received through other channels, such as email or external drives.

How should I respond to this vulnerability?

Begin by identifying which workstations or devices have Power Archiver installed. Since this is client-side software, coordinate with your endpoint or workstation management teams to locate these installations. Once identified, evaluate the necessity of the software on those machines and monitor official updates from the vendor to remediate the vulnerability on all affected systems.

References