Compression tool 7-Zip pwned, pain flows to top security, software tools
Some of the world's biggest security and software vendors will be rushing to patch holes in implementations of the popular 7-zip compression tool to stop attackers gaining full control of customer machines.
Cisco security researcher Jaeson Schultz found and reported the holes to the maintainers of the open source 7-Zip platform who kindly cooked up a fix.
Schultz told The Register the flaws could allow attackers to compromise updated machines, giving attackers the same access rights as logged-in users. "Anytime the vulnerable code is being run by any sort of privileged account, an attacker can exploit the vulnerability and execute code under those same permissions," Schultz says.