Free Archive Program 7-Zip Can Be Hacked With a Malicious File
Free Archive Program 7-Zip Can Be Hacked With a Malicious File reports that the widely used Windows file-archiving tool is vulnerable to malware delivery. The advisory, posted last week, says a hacker could abuse the flaw when 7-Zip processes a booby-trapped file or visits a malicious website, using “secretly booby-trapped” content to execute rogue code. The issue was attributed to how 7-Zip handles the XZ data compression format and involves specially crafted XZ data that can trigger a coding error leading to a buffer overflow, overwriting adjacent memory. The Zero Day Initiative states that exploitation requires user interaction, specifically that the victim opens a malicious file or visits a malicious page. Researcher Landon Peng uncovered the details, which were kept under wraps to limit attacker use. 7-Zip patched the vulnerability with a June 25 update to version 26.02, but the program lacks an auto-update feature, requiring manual installation. WinRAR, another archiver without auto-update, has faced similar issues.





