Why would it be a vulnerability that AVs don't unpack a malformed ZIP which is not unpacked by any other tool? 😱
https://kb.cert.org/vuls/id/976247CERT/CC Vulnerability Note VU#976247
Antivirus and Endpoint Detection and Response Archive Scanning Engines may not properly scan malformed zip archives