7-Zip plugged the vulnerability last month, but the program doesn’t have an auto-update feature, meaning users must manually install the latest version.
If you use 7-Zip, it’s time to patch. The free file-archiving program on Windows can be exploited to launch malware if it encounters a secretly booby-trapped file or website.
An advisory about the software vulnerability was posted last week, warning that a hacker could abuse the flaw to run rogue computer code via 7-Zip installations.
Details about the flaw, which was uncovered by researcher Landon Peng, remain under wraps to prevent attackers from exploiting it. But the report indicates that the problem stems from how 7-Zip processes the XZ data compression format. Specially crafted XZ data can trigger a software coding error in the program, leading to a buffer overflow, in which extra data spills into adjacent memory sections, overwriting them.
“An attacker can leverage this vulnerability to execute code in the context of the current process,” says the advisory from the Zero Day Initiative, which independent security researchers use to disclose flaws. “User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.”
7-Zip is often used to open compressed archive files. So, it’s not hard to see how a hacker could exploit the vulnerability by circulating malicious XZ archives online to deliver malware to PCs running the free software. 7-Zip has been around since 1999 and has likely been downloaded tens of millions of times.
7-Zip patched the vulnerability with a June 25 update (version 26.02). However, the program lacks an auto-update feature, so users must download and install the latest version to remain protected.
WinRAR, another free and popular archiving program, has suffered similar flaws and also lacks an auto-update function. As a result, hackers have been able to continue targeting vulnerable WinRAR users, despite the availability of a patch.