New Articles
Windows 11 users have discovered a funny bug that benefits older computers....
It's easy to turn off the transmission — we tell you how to do it....
Such photos have been taken by models and social media users for a long time,...
A famous musician? A schoolteacher? Mom? Tell us about the people you looked up...
Thanks to the instructions of Artyom Kozoriz, you can cope no worse than a...
5 interesting exercises that will help you develop flexibility....
From "Starship Troopers" and "The Matrix" to...
The return of Garfield and Mufasa, the new Transformers and the Lord of the...
Trickben.com » Windows » A serious vulnerability has been discovered in the 7-Zip archiver for Windows

A serious vulnerability has been discovered in the 7-Zip archiver for Windows

03 May 2023, 06:42, parser
0 comments    0 Show

A serious vulnerability has been discovered in the free open source 7-Zip archiver. It is able to provide an attacker with administrator-level access without the need to crack the password, using a bundle of 7-Zip and Windows Help.

The video below shows how the user who discovered the vulnerability exploits it. He drags a fake file with an extension .7z, simulating a 7-Zip archive, in the help window of the program, which allows it to execute commands on behalf of the administrator. This gives access to a higher-level system and provides access to programs and commands that would normally require a password.

This vulnerability is present in all versions of the Windows application, the developers have not yet had time to close it. If this bothers you, it is not necessary to delete the program: you can only restrict its rights by allowing only reading and execution.

Read also 🧐
  • 10 useless Windows 10 components that should be disabled and removed
  • A vulnerability was found on the iPhone that allows you to simulate a reboot and monitor users
  • A critical vulnerability has been found in Windows 10. Because of her, one line of code breaks the hard drive
Comments
reload, if the code cannot be seen