7-zip

7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now

Teilen:

​A high-severity vulnerability in the 7-Zip file archiver allows attackers to bypass the Mark of the Web (MotW) Windows security feature and execute code on users’ computers when extracting malicious files from nested archives.

7-Zip added support for MotW in June 2022, starting with version 22.00. Since then, it has automatically added MotW flags (special ‘Zone.Id’ alternate data streams) to all files extracted from downloaded archives.

This flag informs the operating system, web browsers, and other applications that files may come from untrusted sources and should be treated with caution.

As a result, when double-clicking risky files extracted using 7-Zip, users will be warned that opening or running such files could lead to potentially dangerous behavior, including installing malware on their devices.

Microsoft Office will also check for the MotW flags, and if found, it will open documents in Protected View, which automatically enables read-only mode and disables all macros.

Launching a downloaded executable with a MoTW flag
Launching a downloaded executable with a MoTW flag (BleepingComputer)

However, as Trend Micro explained in an advisory published over the weekend, a security flaw tracked as CVE-2025-0411 can let attackers bypass these security warnings and execute malicious code on their targets’ PCs.

“This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file,” Trend Micro says.

“The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.”

Luckily, 7-Zip developer Igor Pavlov has already patched this vulnerability on November 30, 2024, with the release of 7-Zip 24.09.

“7-Zip File Manager didn’t propagate Zone.Identifier stream for extracted files from nested archives (if there is open archive inside another open archive),” Pavlov said.

Similar flaws exploited to deploy malware

However, since 7-Zip doesn’t have an auto-update feature, many users are likely still running a vulnerable version that threat actors could exploit to infect them with malware.

All 7-Zip users should patch their installs as soon as possible, considering that such vulnerabilities are often exploited in malware attacks.

For instance, in June, Microsoft addressed a Mark of the Web security bypass vulnerability (CVE-2024-38213) that DarkGate malware operators have exploited in the wild as a zero-day since March 2024 to circumvent SmartScreen protection and install malware camouflaged as installers for Apple iTunes, NVIDIA, Notion, and other legitimate software.

The financially motivated Water Hydra (aka DarkCasino) hacking group has also exploited another MotW bypass (CVE-2024-21412) in attacks targeting stock trading Telegram channels and forex trading forums with the DarkMe remote access trojan (RAT).

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:19 pm, Mai 17, 2025
Wetter-Symbol 18°C
L: 18° | H: 20°
klarer Himmel
Luftfeuchtigkeit: 52 %
Druck: 1021 mb
Wind: 2 mph NNW
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:05 am
Sonnenuntergang: 8:48 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 7 mph 57 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
9° | 16°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Mo. Mai 19 10:00 pm
Wetter-Symbol
11° | 19°°C 0.2 mm 20% 13 mph 78 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 21°°C 0.35 mm 35% 9 mph 81 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
11° | 20°°C 0.09 mm 9% 11 mph 79 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 7 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 5 mph 68 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 83 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 69 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 52 % 1021 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 49 % 1020 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 56 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,469.39
-0.76%
Ethereum(ETH)
€2,216.49
-4.21%
Fesseln(USDT)
€0.90
0.00%
XRP(XRP)
€2.09
-3.16%
Solana(SOL)
€148.92
-2.69%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.192512
-5.18%
Shiba Inu(SHIB)
€0.000013
-5.14%
Pepe(PEPE)
€0.000011
-8.19%
Peanut das Eichhörnchen(PNUT)
€0.269711
-10.27%
Nach oben scrollen