HomeSecurity7-Zip vulnerability allows hackers to execute arbitrary code

7-Zip vulnerability allows hackers to execute arbitrary code

A serious vulnerability has been discovered in 7-Zip, the popular file compression tool, that allows remote hackers to execute malicious code via specially crafted files.

7-Zip vulnerability

The vulnerability, known as CVE-2024-11477, has been rated with a high CVSS score of 7.8, indicating significant security risks for users of affected versions. The issue is located in the Zstandard decompression implementation, where insufficient validation of user data can lead to an integer underflow before writing to memory.

Read also: Zimbra fixes serious zero-day vulnerability

This vulnerability allows hackers to execute arbitrary code within the current process when users interact with malicious files. According to Nicholas Zubrisky of Trend Micro Security Research, hackers can exploit this vulnerability by convincing users to open specially crafted files, which could be distributed via email attachments or shared files.

The Zstandard format, particularly prevalent in Linux environments , is widely used in file systems such as Btrfs, SquashFS, and OpenZFS. The vulnerability poses significant risks, allowing attackers to execute arbitrary code, gaining the same access rights as users, and potentially leading to a complete system compromise.

7-zip vulnerability

See also: Microsoft Patch Tuesday June 2024: Fixes 51 vulnerabilities

7-Zip addressed this security issue in version 24.07. Since the software does not have a built-in update mechanism, users must manually download and install the latest version to ensure their systems are protected . IT administrators and developers who integrate 7-Zip into their products should immediately update their installations to the patched version. Security experts emphasize the importance of applying patches promptly.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS