Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Tips & Tricks Work around for security issue in 7-Zip until it is fixed

Wichestery2k

👑 Administrator
Super Moderator
Moderator
Uploader
Power User
✅ Verified Member
Downloaded
1.4 TB
Uploaded
52.5 TB
Ratio
38.76
Seedbonus
37,032
Upload Count
254 (262)
Member for 7 years
Recent versions of the open source archiver 7-Zip have a vulnerability that has not been fixed yet. Successful exploitation of the vulnerability allows privilege escalation and the execution of commands; it appears that the issue can be exploited locally only.

7-zip vulnerability workaround
QUVJZc.png


Filed under CVE-2022-29072, the vulnerability is using the included 7-Zip Help file, 7-zip.chm, for the exploit. Attackers need to drag and drop files with the 7z extension on to the Help > Contents area in the 7-Zip interface.

Vulnerability details have been published on GitHub. The page provides technical information and a short demonstration video of the exploit.

It is unclear if and when 7-Zip will address the issue. The last update of the application dates back to the release of 7-Zip in December 2021

Users of the application may use the following workaround to mitigate the vulnerability on their devices. Since it is using the included Help file, one way of dealing with the issue is to delete the Help file.

Open the 7-Zip installation directory or folder on the system. On Windows, these are usually C:\Program Files\7-Zip or C:\Program Files (x86)\7-Zip, depending on whether the 64-bit or the 32-bit version of the application has been installed.
Locate the file 7-Zip.chm; this is the help file. You can open it directly to display its content.
Hit the delete button on the keyboard or right-click on the file and select the Delete context menu option, to remove it from the system.
You may get a prompt, File Access Denied. If that is the case, select Continue.

The file is moved to the recycle bin of the operating system by default. 7-Zip functionality is not reduced when you delete the help file. The Help file won't open anymore after the deletion, when you select Help > Contents in the 7-Zip File Manager or press the F1-key on the keyboard.

Closing Words

Deleting the Help file does not take longer than a minute. While it appears unlikely that the issue is exploited on large scale, most users may want to remove the Help file to protect their systems against exploits targeting the issue.
 
Last edited:

SydneyM

✅ Verified Member
Member
Downloaded
51.6 GB
Uploaded
57.4 GB
Ratio
1.11
Seedbonus
2,845
Upload Count
0 (0)
Member for 8 years
Thanks for the heads up @Wichestery2k; done.;)
 

Uncle Mac

🤴 Super Admin
Downloaded
91.3 GB
Uploaded
305.8 TB
Ratio
3429.49
Seedbonus
3,466,026
Upload Count
333 (352)
Member for 10 years
I did it also then I searched windows for *.chm and lots came up.
 

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
I did it also then I searched windows for *.chm and lots came up.

It is correct, it is still being used, although Microsoft (developer of this help system) said that starting with Windows Vista it was going to replace it with Microsoft Assistance Markup Language, but they have not done so. :p
 

PsyTom

Power User
✅ Verified Member
Member
Downloaded
1.4 TB
Uploaded
502.1 TB
Ratio
367.69
Seedbonus
1,662,990
Upload Count
0 (0)
Member for 3 years
very detailed ,thanx for such a wonderful share. greetings!
 
Top