7-Zip compression program,software contains a severe vulnerability.
What makes the threat particularly dangerous is not just because it is being utilized, but also because it allows a person to remotely execute malware on an computer.
7-zip, one of the world's most popular file compressors, contains a zero-day vulnerability that might allow an attacker to get administrator access. Although compression software is available for many platforms, it appears that the CVE-2022-29072 flaw now affects just Windows users. The discoverer, a GitHub user called Kagancapar, detailed how the weakness works and provided a video illustrating how it may be abused. According to the researcher, the problem, which may be ascribed to the way the Windows assistance system works, is not solely the responsibility of the 7-Zip creators. An attacker just has to generate a file with the.7z extension, which, when dragged onto the program's help page, offers the ability to execute code on the system with administrator rights.
According to Kangacapar, the obligation of the designers of 7-Zip comes when, after dragging the file, the executable ends up with certain access capabilities that it should not have. The issue affects all Windows versions of the application, including the most recent (21.97), which has yet to be patched.
To protect yourself, remove the 7-zip.chm file from the program installation location or restrict its read and write rights. In the latter instance, the setting must be performed on all users who have access to the computer in order to ensure its security. Commenting on the issue, the fact that the problem has been made public should encourage the deployment of a remedy as soon as possible. The tool was released in 1999 as a free alternative to popular alternatives such as WinRAR and is now available in 89 languages for Windows, BSD, MacOS, Linux, and ReactOS.
Member
Posts: 61
Joined: 2016-07-20
Winrar and 7zip are pretty much the best you can get. Winrar is actually better, because you can customize it more and you can add recovery informations on the archive created. Also, I noticed that if you wants to pack a series of images in a cbr/cbz file (the format used to read the digital comics), 7zip gives errors, while winrar always work (the process needs to create a zip archive saved with the extension cbr or cbz).
I tried winzip and it's improved a lot and has also the ability to use the gpu acceleration. I was able to compress very big folders full of files in few seconds compared to 7zip, using a RX480. But at the moment the best level of compression needs the file format .zipx, that it's not supported by 7zip. Also, I find it difficult to customize the right click menu explorer.
The best would be a winrar build with opencl acceleration support.
Senior Member
Posts: 1822
Joined: 2005-08-12
Just take a look at Sourceforge discussion - it totally looks like a scam
https://sourceforge.net/p/sevenzip/bugs/2337/
Help file viewer executes a file... great - you could drag CMD with virtually the same effect.
Priv escalation - without 7-zip process running as system, you can hardly think of 7-zip exposing system user.
Senior Member
Posts: 2953
Joined: 2013-03-10
I don't even know what's supposed to be 7-zip's "help page" and why I should drag'n'drop files there in the first place. So, regardless of the exploit being real or not, it seems pretty safe.
Junior Member
Posts: 13
Joined: 2010-03-12
The constant fire alarms for clicks that all these sites do with vulnerabilities is getting REALLY annoying. Especially since I'm a sysadmin.
Some brainless exec reads an article and thinks the end of the world is coming. Let's rush a patch out by today without testing!
Senior Member
Posts: 259
Joined: 2016-10-22
I was thinking that some program could offer an overall improvement, or is 7-zip just strictly the best?