B1 Free Archiver Mark of the Web Bypass Vulnerability

Vulnerability

A vulnerability in B1 Free Archiver version 1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. The software fails to transfer the 'Zone.Identifier' alternate data stream to extracted files, enabling execution without triggering Windows Defender SmartScreen warnings or security prompts. This flaw could lead to untrusted code execution without standard security restrictions.

Impact

Exploiting this vulnerability causes extracted files to be treated as trusted by Windows, allowing them to be executed without any warnings or prompts. This could facilitate the execution of malicious code or delivery of malware, potentially leveraging social engineering tactics.

Reproduction

To reproduce this vulnerability, download a '7Z.zip' file from the internet that contains an executable. After downloading, extract the file using B1 Free Archiver. Once extracted, check the 'Zone.Identifier' alternate data stream to confirm that the MotW has not been applied.

Added: Apr 29, 2026, 9:24 PM
Updated: Apr 29, 2026, 9:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
5.6
remediation
0.0
relevance
6.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.