Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
ID: a52083cd-526f-56dd-baaa-f1c65557f42c
STIX ID: report--a52083cd-526f-56dd-baaa-f1c65557f42c
Feed Name: Bleeping Computer
Threat Score
7-Zip released version 26.02 to fix a heap-based buffer overflow in its XZ decompression that could enable arbitrary code execution when a user opens specially crafted compressed files; the patch adds bounds checks to prevent writes beyond available output buffer space. Exploitation requires user interaction (e.g., opening a malicious archive or visiting a page) and there are no reports of active exploitation, so users must update manually because 7-Zip lacks automatic updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
