# CVE-2025-46652

## Summary

- **CVE ID:** CVE-2025-46652
- **Severity:** MEDIUM
- **CVSS Score:** 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **CWE:** CWE-830
- **Published:** Apr 26, 2025
- **Last Modified:** Mar 13, 2026

## Description

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

## Affected Products

- IZArc — IZArc (0)

## References

- [CNA](https://github.com/EnisAksu/Argonis/blob/main/CVEs/IZArc/IZArc%20Mark-of-the-Web%20Bypass%20Vulnerability.md)
- [CNA](https://github.com/EnisAksu/Argonis/security/advisories/GHSA-637g-8v47-79mv)
- [CNA](https://www.izarc.org/news)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._