Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip 26.02 fixes a remote code execution flaw in its XZ decompression handling that could let attackers run arbitrary code through a specially crafted archive. Users should install the update manually from 7-zip.org, as there is no automatic updater, to reduce the risk of phishing-delivered attacks and future exploitation. #7Zip #LandonPeng #XZ

Keypoints

  • 7-Zip 26.02 patches a remote code execution vulnerability.
  • The flaw affects processing of XZ-compressed data.
  • Specially crafted data could trigger a heap-based buffer overflow.
  • Exploitation requires user interaction, such as opening a malicious archive.
  • Users must manually update from the official 7-Zip website.

Read More: https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/