Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
Vulnerability Description
7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Vulnerability Type
保护机制失效
Vulnerability Title
7-Zip 处理逻辑错误漏洞
Vulnerability Description
7-Zip是7-Zip个人开发者开源的一个压缩软件。 7-Zip 26.02及之前版本存在处理逻辑错误漏洞,该漏洞源于提取特制RAR5归档时未能保留Web标记,允许攻击者绕过SmartScreen/MotW警告并篡改文件内容。
CVSS Information
N/A
Vulnerability Type
N/A