Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Corsair RM1200X SHIFT 1200W PSU Review
Intel NUC 13 Pro (Arena Canyon) review
Endorfy Arx 700 Air chassis review
Beelink SER5 Pro (Ryzen 7 5800H) mini PC review
Crucial T700 PCIe 5.0 NVMe SSD Review - 12GB/s
Sapphire Radeon RX 7600 PULSE review
Gainward GeForce RTX 4060 Ti GHOST review
Radeon RX 7600 review
ASUS GeForce RTX 4060 Ti TUF Gaming review
MSI GeForce RTX 4060 Ti Gaming X TRIO review

New Downloads
CrystalDiskInfo 9.0.1a Download
AMD Radeon Software Adrenalin 23.5.2 WHQL download
Intel ARC graphics Driver Download Version: 31.0.101.4382
Corsair Utility Engine Download (iCUE) Download v5.2
GeForce 535.98 WHQL driver download
CPU-Z download v2.06
AMD Radeon Software Adrenalin 23.5.1 WHQL download
GeForce 532.03 WHQL driver download
AMD Chipset Drivers Download 5.05.16.529
Display Driver Uninstaller Download version 18.0.6.4


New Forum Topics
Intel Introduces Breakthrough Power Delivery Technique for Next-Generation Processors - PowerVia PSA: 535 system stability concerns. Third party Graphics Card hardware database Extreme 4-Way Sli Tuning AMD's Future Developments: Ryzen 8000 and Navi 3.5 Nvidia Driver & COD MW2 NVIDIA GeForce Hotfix Driver 536.09 Researchers Expose Vulnerabilities in AMD's Firmware-Based TPMs Seby9123 Emerges as OC Champion in G.SKILL OC World Cup 2023 AMD EPYC 7002 Server Processors Reportedly Harbour a Bug - Crashes After 1044 Days of Uptime




Guru3D.com » News » 7-Zip compression program,software contains a severe vulnerability.

7-Zip compression program,software contains a severe vulnerability.

by Hilbert Hagedoorn on: 04/22/2022 06:39 PM | source: hd-tecnologia | 41 comment(s)
7-Zip compression program,software contains a severe vulnerability.

What makes the threat particularly dangerous is not just because it is being utilized, but also because it allows a person to remotely execute malware on an computer.

7-zip, one of the world's most popular file compressors, contains a zero-day vulnerability that might allow an attacker to get administrator access. Although compression software is available for many platforms, it appears that the CVE-2022-29072 flaw now affects just Windows users. The discoverer, a GitHub user called Kagancapar, detailed how the weakness works and provided a video illustrating how it may be abused. According to the researcher, the problem, which may be ascribed to the way the Windows assistance system works, is not solely the responsibility of the 7-Zip creators. An attacker just has to generate a file with the.7z extension, which, when dragged onto the program's help page, offers the ability to execute code on the system with administrator rights.


According to Kangacapar, the obligation of the designers of 7-Zip comes when, after dragging the file, the executable ends up with certain access capabilities that it should not have. The issue affects all Windows versions of the application, including the most recent (21.97), which has yet to be patched.

To protect yourself, remove the 7-zip.chm file from the program installation location or restrict its read and write rights. In the latter instance, the setting must be performed on all users who have access to the computer in order to ensure its security. Commenting on the issue, the fact that the problem has been made public should encourage the deployment of a remedy as soon as possible. The tool was released in 1999 as a free alternative to popular alternatives such as WinRAR and is now available in 89 languages for Windows, BSD, MacOS, Linux, and ReactOS.

 







« Review: Deepcool CK560 chassis · 7-Zip compression program,software contains a severe vulnerability. · Advertisement: April sale: best price Genuine lifetime computer software Windows 10 $12 and Office $25 »

9 pages « < 6 7 8 9


Kaerar
Senior Member



Posts: 366
Joined: 2003-10-26

#6011963 Posted on: 04/25/2022 06:38 AM
Hey Hilbert, feel like doing a follow up article pointing out that Kagan Capar is just a hacker blackmailing software dev's?

9 pages « < 6 7 8 9


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2023