{"id":11457,"date":"2025-07-22T12:30:54","date_gmt":"2025-07-22T05:30:54","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11457"},"modified":"2026-06-25T09:59:50","modified_gmt":"2026-06-25T02:59:50","slug":"new-7-zip-vulnerability-can-cause-application-to-crash-when-extracting-malicious-rar5-files","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/22\/new-7-zip-vulnerability-can-cause-application-to-crash-when-extracting-malicious-rar5-files\/","title":{"rendered":"New 7-Zip vulnerability can cause application to &#8221; crash &#8221; when extracting malicious RAR5 files"},"content":{"rendered":"<div style=\"text-align: justify\"><b>A vulnerability was recently discovered in the popular decompression software 7-Zip, which could cause the application to collapse completely when processing a maliciously edited RAR5 file. While this does not allow hackers to gain control of the machine, it is sufficient to create a Do Not Service (DoS) situation, causing the software or system to be disrupted, suspended, or paralyzed.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1753171211998-png.17351\/\" target=\"_blank\" rel=\"noopener\" data-caption=\"&lt;h4&gt;1753171211998.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;lo-hong-7-zip-moi-co-the-khien-ung-dung-sap-khi-giai-nen-file-rar5-doc-hai.18589&amp;#x2F;#post-44098&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 22&amp;#x2F;07&amp;#x2F;2025 l\u00fac 3:01 PM&lt;\/a&gt;&lt;\/p&gt;\" data-fancybox=\"lb-thread-18589\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753171211998.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17686-f9409c4fac95d3107740009223934a3d.jpg\" alt=\"1753171211998.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<div style=\"text-align: justify\">\n<p>The bug was officially patched in version 7 &#8211; Zip 25.00, released on July 5, 2025.<\/p>\n<p>The vulnerability is in the RAR5 compression format processor, a common compression standard. When you run into a corrupted archive, 7-Zip tries to &#8220;cure&#8221; it by filling in a &#8220;0&#8221; to replace the error. But due to the miscalculation of the memory size required, the software overruled beyond the allowed memory range, resulting in &#8220;memory leak&#8221; and application crash.<\/p>\n<p>This phenomenon is known as heap buffer overflow, where software writes data beyond the allocated memory limit, leading to uncontrolled behavior and even crashes.<\/p>\n<p>This error does not help hackers control the machine but is extremely dangerous if you accidentally unzip a malicious RAR5 file:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">7-Zip will close abruptly, disrupting your work.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">This may affect automatic decompression in large systems, servers, or CI\/CD tool chains.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">In a corporate or high &#8211; security environment, this can be a gateway to further exploitation if not well controlled.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>Security researchers created a sample file called &#8220;rar-crash.rar5&#8221; to prove the error, and used the AddSanitizer to detect overwritten data areas. The results showed that 7-Zip was written out of the cache, causing serious errors and turning the program off.<\/p>\n<p>All users of 7-Zip versions 12.97 through before 25.00 can be affected by right-opening malicious RAR5 files. The impact is greater if 7-Zip is used in server systems, CI\/CD tools, or in mass file organizations. The risk of remote mining is low but the possibility of DoS attacks (application crashes) is certain, especially if the file is used in an automated process.<\/p>\n<p>Solutions and recommendations for users<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">It is recommended that you update to 7-Zip 25.00 or later immediately to avoid exploitation.<\/li>\n<li data-xf-list-type=\"ul\">The business may consider:\n<ul>\n<li data-xf-list-type=\"ul\">Check the archive file before unpacking, especially if it came from an unknown source.<\/li>\n<li data-xf-list-type=\"ul\">Sandbox the unzipping process, avoiding errors affecting the main system.<\/li>\n<li data-xf-list-type=\"ul\">Log and monitor the automated decompression system for unusual crashes.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">While not a serious permission loophole, this incident serves as a reminder that even popular and well-established software like 7-Zip inevitably slips. In an age of constant file exchange, a seemingly simple error can become a &#8220;death factor&#8221; if taken advantage of at the right time by a bad person.<\/div>\n<div style=\"text-align: right\"><b><i>According to Synthetic WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/lo-hong-7-zip-moi-co-the-khien-ung-dung-sap-khi-giai-nen-file-rar5-doc-hai.18589\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/lo-hong-7-zip-moi-co-the-khien-ung-dung-sap-khi-giai-nen-file-rar5-doc-hai.18589\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A vulnerability was recently discovered in the popular decompression software 7-Zip, which could cause the application to collapse completely when processing a maliciously edited RAR5 file. While this does not allow hackers to gain control of the machine, it is sufficient to create a Do Not Service (DoS) situation, causing the software or system to [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11457","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11457"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11457\/revisions"}],"predecessor-version":[{"id":11648,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11457\/revisions\/11648"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}