Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
DeepCool LS720 (LCS) review
Fractal Design Pop Air RGB Black TG review
Palit GeForce GTX 1630 4GB Dual review
FSP Dagger Pro (850W PSU) review
Razer Leviathan V2 gaming soundbar review
Guru3D NVMe Thermal Test - the heatsink vs. performance
EnGenius ECW220S 2x2 Cloud Access Point review
Alphacool Eisbaer Aurora HPE 360 LCS cooler review
Noctua NH-D12L CPU Cooler Review
Silicon Power XPOWER XS70 1TB NVMe SSD Review

New Downloads
Prime95 download version 30.9 build 1
Intel ARC graphics Driver Download Version: 30.0.101.1743
AMD Radeon Software Adrenalin 22.6.1 WHQL driver download
GeForce 516.59 WHQL driver download
Media Player Classic - Home Cinema v1.9.22 Download
AMD Chipset Drivers Download v4.06.10.651
CrystalDiskInfo 8.17 Download
AMD Radeon Software Adrenalin 22.6.1 Windows 7 driver download
ReShade download v5.2.2
HWiNFO Download v7.26


New Forum Topics
Review: DeepCool LS720 (LCS) MSI AB / RTSS development news thread AMD Might Release and Add Ryzen 5 5600X3D, Ryzen 9 5900X3D (X3D) procs Can you measure if a CPU was used before? Today I bought an FX-8350 NVIDIA GeForce 516.59 WHQL driver download & Discussion EK Launches PCIe 4.0 GPU Vertical Bracket [3rd-Party Driver] Amernime Zone Radeon Insight 22.5.1 WHQL Driver Pack (Released) be quiet! Launches Silent Wings 4 and Silent Wings Pro 4 Fans Sharkoon Launches PureWriter RGB White




Guru3D.com » News » 7-Zip compression program,software contains a severe vulnerability.

7-Zip compression program,software contains a severe vulnerability.

by Hilbert Hagedoorn on: 04/22/2022 06:39 PM | source: hd-tecnologia | 41 comment(s)
7-Zip compression program,software contains a severe vulnerability.

What makes the threat particularly dangerous is not just because it is being utilized, but also because it allows a person to remotely execute malware on an computer.

7-zip, one of the world's most popular file compressors, contains a zero-day vulnerability that might allow an attacker to get administrator access. Although compression software is available for many platforms, it appears that the CVE-2022-29072 flaw now affects just Windows users. The discoverer, a GitHub user called Kagancapar, detailed how the weakness works and provided a video illustrating how it may be abused. According to the researcher, the problem, which may be ascribed to the way the Windows assistance system works, is not solely the responsibility of the 7-Zip creators. An attacker just has to generate a file with the.7z extension, which, when dragged onto the program's help page, offers the ability to execute code on the system with administrator rights.


According to Kangacapar, the obligation of the designers of 7-Zip comes when, after dragging the file, the executable ends up with certain access capabilities that it should not have. The issue affects all Windows versions of the application, including the most recent (21.97), which has yet to be patched.

To protect yourself, remove the 7-zip.chm file from the program installation location or restrict its read and write rights. In the latter instance, the setting must be performed on all users who have access to the computer in order to ensure its security. Commenting on the issue, the fact that the problem has been made public should encourage the deployment of a remedy as soon as possible. The tool was released in 1999 as a free alternative to popular alternatives such as WinRAR and is now available in 89 languages for Windows, BSD, MacOS, Linux, and ReactOS.

 







« Review: Deepcool CK560 chassis · 7-Zip compression program,software contains a severe vulnerability. · Advertisement: April sale: best price Genuine lifetime computer software Windows 10 $12 and Office $25 »

9 pages 1 2 3 4 > »


GamerNerves
Senior Member



Posts: 259
Joined: 2016-10-22

#6011524 Posted on: 04/22/2022 07:29 PM
Just keep using this program. Just because there is vulnerability doesn't mean you can trigger it in practice. The fact there is even a dispute means it's far than straightforward to trigger it.


I was thinking that some program could offer an overall improvement, or is 7-zip just strictly the best?

gianluca
Member



Posts: 61
Joined: 2016-07-20

#6011534 Posted on: 04/22/2022 08:49 PM
I was thinking that some program could offer an overall improvement, or is 7-zip just strictly the best?

Winrar and 7zip are pretty much the best you can get. Winrar is actually better, because you can customize it more and you can add recovery informations on the archive created. Also, I noticed that if you wants to pack a series of images in a cbr/cbz file (the format used to read the digital comics), 7zip gives errors, while winrar always work (the process needs to create a zip archive saved with the extension cbr or cbz).
I tried winzip and it's improved a lot and has also the ability to use the gpu acceleration. I was able to compress very big folders full of files in few seconds compared to 7zip, using a RX480. But at the moment the best level of compression needs the file format .zipx, that it's not supported by 7zip. Also, I find it difficult to customize the right click menu explorer.

The best would be a winrar build with opencl acceleration support.

Ven0m
Senior Member



Posts: 1822
Joined: 2005-08-12

#6011536 Posted on: 04/22/2022 08:53 PM
Just take a look at Sourceforge discussion - it totally looks like a scam
https://sourceforge.net/p/sevenzip/bugs/2337/

Help file viewer executes a file... great - you could drag CMD with virtually the same effect.
Priv escalation - without 7-zip process running as system, you can hardly think of 7-zip exposing system user.

Kaarme
Senior Member



Posts: 2953
Joined: 2013-03-10

#6011537 Posted on: 04/22/2022 08:55 PM
I don't even know what's supposed to be 7-zip's "help page" and why I should drag'n'drop files there in the first place. So, regardless of the exploit being real or not, it seems pretty safe.

Coupe
Junior Member



Posts: 13
Joined: 2010-03-12

#6011540 Posted on: 04/22/2022 09:23 PM
The constant fire alarms for clicks that all these sites do with vulnerabilities is getting REALLY annoying. Especially since I'm a sysadmin.

Some brainless exec reads an article and thinks the end of the world is coming. Let's rush a patch out by today without testing!

9 pages 1 2 3 4 > »


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2022