Skip to content
7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can be triggered through a specially crafted archive. If a user opens the malicious file, an attacker could exploit a heap-based buffer overflow to execute arbitrary code with the user’s privileges. The developer has not released techn...
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ | Huntaegis