A critical vulnerability in 7-Zip, affecting its handling of XZ-compressed files, has been discovered, allowing for potential remote code execution if a user opens a malicious archive. This flaw, identified by researcher Landon Peng, exploits a heap-based buffer overflow. Users are encouraged to update to version 26.02, as the software does not support automatic updates. The exploit requires user interaction, such as opening a crafted file. Previous vulnerabilities in 7-Zip have seen active exploitation, highlighting the risk associated with popular software.
7zip XZ file flaw lets hackers run code via malicious archive
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
7zip XZ file flaw lets hackers run code via malicious archive
securityaffairs.com
-
Malicious XZ archives can execute code via 7Zip flaw, patch urged
thehackernews.com