Crypto Ticker:
sysadmin from Cyber Security News

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

Tushar Subhra Dutta
4 hours ago
3 Views
0 Comments
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP archives are common in phishing campaigns. The gap grows when an archive looks like an invoice, update, or shared document. An attacker sends a link or attachment that leads to an archive, persuades the recipient to extract it with 7-Zip, then relies on the unmarked file being launched. This is not a newly disclosed exploit in 7-Zip code, but a security-control gap caused by the program’s default handling of download-origin metadata. Attackd analysts identified the behavior while testing phishing delivery...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!