A security flaw in 7-Zip allows remote code execution when a malicious archive is downloaded and then extracted. Users should install version 26.02 to fix this vulnerability.
A major security vulnerability has been discovered in 7-Zip software. After tricking the victim into downloading and extracting a specially crafted archive, an attacker can exploit this flaw to execute arbitrary code remotely. Ultimately, the victim may end up with malware on their computer. Fortunately, an update was deployed, but it was not applied automatically. Here’s what to do.
A major security flaw in 7-Zip’s software
As BleepingComputer reports, a major security flaw has been discovered in 7-Zip software. As a reminder, 7-Zip is a program intended to compress or decompress files (.zip, .rar, .tar, etc.) on a computer. It is therefore a particularly useful program, which is also free and open source. But a security flaw has now transformed it into a potential threat to the computers where it is installed.
To be more precise, this flaw allows executing arbitrary code from a distance. Firstly, the criminal must encourage the victim to download an archive specially designed to exploit the flaw. He can do this in different ways: by sending it by email, by distributing it via a compromised website or by sharing it via instant messaging. Once the archive is opened or extracted with a vulnerable version of 7-Zip, the attacker can potentially execute code remotely on the machine. They can then install malware, steal data or carry out other malicious actions.
How to protect yourself from it?
Good news, an update has already been deployed, but it is important to clarify that it was not applied automatically. If you have not already done so, it is essential to download update 26.02 from the project website. Once the patch is applied, the vulnerability will be closed. Incidentally, this reminds us to think before downloading a file from a site or instant messaging platform.
👉🏻 Follow tech news in real time: add 01net to your sources on Google, and subscribe to our WhatsApp channel.
Source :
Bleeping Computer
