Socprime
Critical Vulnerabilities in 7-Zip Enable Code Execution Attacks
Article Content
A critical heap buffer overflow vulnerability has been identified in 7-Zip version 26.00, allowing attackers to execute arbitrary code through a vtable hijack. This flaw, tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, affects the NTFS archive handler, specifically within the CInStream::GetCuSize() function in NtfsHandler.cpp. Attackers can exploit this vulnerability by crafting malicious archive files that, when opened by victims, can lead to remote code execution and sensitive data leakage. The GitHub Security Lab has disclosed this vulnerability, emphasizing its severity. Users of 7-Zip are advised to update to the latest version to mitigate risks associated with this flaw.
Key Points: • 7-Zip version 26.00 has a critical heap buffer overflow vulnerability (CVE-2026-48095). • Attackers can exploit this flaw via crafted NTFS archive files to execute arbitrary code. • Users are urged to update 7-Zip to the latest version to protect against these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.