• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
WebSetNet

WebSetNet

Technology News

  • Technology News
    • Mobile
    • Games
  • Internet Marketing
  • System Admin
    • Windows
    • Linux
    • Mac & Apple
    • Website Scripts
      • Wordpress

New 7-Zip Archiver Hack Reveals a Long Ignored Windows Vulnerability

April 21, 2022 by Martin6

The latest versions of 7-Zip contain a vulnerability (CVE-2022-29072) that lets hackers gain administrative privileges on a system. But this vulnerability, which exploits the 7-Zip help file, should alarm all Windows users, as it highlights an age-old problem on Windows systems.

How Does the Exploit Work?

As you may know, 7-Zip is a pretty old piece of open-source software. Its interface, buttons, and help menu haven’t changed much since 1999. The help menu is especially nostalgic—it relies on a .chm help file, which is a relic from the days of Windows 98.

These old .chm files are pretty versatile. When opened, they can display HTML and Javascript, making them a solid option for e-books, dictionaries, and other documentation. But they’re also easily exploited, as they can run malicious code and effectively substitute for an executable.

Now, 7-Zip’s help file doesn’t contain malware. But as kagancapar explains, hackers can use this file to execute malicious code on your system.

The process here is a bit wonky, so stay with me. Hackers with local or remote access to your computer can drag a .7z archive into the 7-Zip help menu to open a command prompt with admin privileges. The cmd.exe prompt runs as a child process under 7zFM.exe, which is quite odd.

A misconfiguration in the 7z.dll file and heap overflow appear to be responsible for this problem. Normally, dragging a file into the 7-Zip help menu should do nothing. I should note that a similar problem recently affected WinRAR, another archiving tool.

Realistically, the average person won’t be affected by this exploit. It requires local or remote access to your computer, and if a hacker manages to get that far, then you’re already screwed. If you’re worried about this vulnerability, you can simply delete 7zip.chm. It should be under C:Program Files7-Zip or C:Program Files (x86)7-Zip, depending on whether you use the 64-bit or 32-bit version.

Note that this problem only seems to affect the latest version of 7-Zip (21.07). This particular update launched in December of 2021, and 7-Zip hasn’t confirmed plans to patch the problem.

Sill, escaping from this vulnerability may not save you from future .chm exploits, as Microsoft is partially responsible for such hacks.

Microsoft Needs to Address Old Help Files

The Surface Pro 8, Surface Go 3, and upgraded Surface Pro X

By default, Windows tries to open .chm files in the old HTMLHelper, also called hh.exe. This viewer executes HTML and Javascript and provides very little protection from exploits. Hackers are known to use .chm files to run malicious code in HTMLHelper, usually through phishing schemes.

Microsoft has made some lightweight attempts to fight this problem—Outlook no longer opens .chm files, and many .chm files are automatically blocked from running in Windows. But as we see with today’s news, HTMLHelper and .chm files present an ongoing security risk for Windows PCs.

You could blame 7-Zip for leaving bugs in its software, but realistically speaking, a misconfigured .dll file shouldn’t let hackers run malicious code on your computer. The problem lies with Microsoft and its HTMLHelper software.

I suggest avoiding .chm files until Microsoft finds a way to resolve this problem. That said, you shouldn’t uninstall hh.exe, as doing so could negatively impact system performance.

Source: WinFuture

Related posts:

  1. Microsoft December 2020 Patch Tuesday fixes 58 vulnerabilities
  2. Microsoft Windows Security Updates September 2020 overview
  3. Microsoft Windows Security Updates November 2020 overview
  4. A new Minecraft: Bedrock Edition patch update is rolling out to all players
  5. Microsoft Windows Security Updates July 2021 overview
  6. New GeForce drivers optimized for Call of Duty: WWII
  7. Download the MIUI 12 Closed Beta for Xiaomi and Redmi devices
  8. Download: MIUI 11 stable update rolling out to several Xiaomi and Redmi devices!
  9. Microsoft Windows Security Updates June 2019 overview
  10. Running out of storage? Try these tips to free up space on Windows 10

Filed Under: Windows

Primary Sidebar

Trending

  • How to fix Windows Update Error 80244019
  • Windows 10 Update keeps failing with error 0x8007001f – 0x20006
  • How To Change Netflix Download Location In Windows 10
  • Troubleshoot Outlook “Not implemented” Unable to Send Email Error
  • How do I enable or disable Alt Gr key on Windows 10 keyboard
  • How To Install Android App APK on Samsung Tizen OS Device
  • 3 Ways To Open PST File Without Office Outlook In Windows 10
  • FIX: Windows Update error 0x800f0986
  • How to Retrieve Deleted Messages on Snapchat
  • Latest Samsung Galaxy Note 20 leak is a spec dump revealing key features
  • Install Android 7.0 Nougat ROM on Galaxy Core 2 SM-G355H
  • 192.168.1.1 Login, Admin Page, Username, Password | Wireless Router Settings
  • Websites to Watch Movies Online – 10+ Best Websites Without SignUp/Downloading
  • How to Backup SMS Messages on Your Android Smartphone
  • How to delete a blank page at the end of a Microsoft Word document
  • Fix: The Disc Image File Is Corrupted Error In Windows 10
  • Android 11 Custom ROM List – Unofficially Update Your Android Phone!
  • Samsung Galaxy Z Fold 3 could be scheduled for June 2021, with S Pen support

Footer

Tags

Amazon amazon prime amazon prime video Apple Application software epic games Galaxy Note 20 Galaxy S22 Plus Galaxy S22 Ultra Google Sheets headphones Huawei icloud Instagram instant gaming ip address iPhone iphone 12 iphone 13 iphone 13 pro max macOS Microsoft Microsoft Edge Mobile app office 365 outlook Pixel 6 Samsung Galaxy Samsung Galaxy Book 2 Pro 360 Samsung Galaxy Tab S8 Smartphone speedtest speed test teams tiktok Twitter vpn WhatsApp whatsapp web Windows 10 Windows 11 Changes Windows 11 Release Windows 11 Update Windows Subsystem For Android Windows 11 Xiaomi

Archives

  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org