Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

7-Zip Flaw Lets Malicious Files Crash PCs

July 22, 2025
Reading Time: 2 mins read
in Alerts
3.5K Sites Hijacked to Secretly Mine Crypto

A significant denial-of-service vulnerability, identified as CVE-2025-53816, has been found within the popular compression software 7-Zip. This flaw specifically targets the software’s RAR5 decoder, enabling malicious actors to trigger system crashes. The vulnerability stems from a heap buffer overflow that occurs when 7-Zip attempts to process specially crafted RAR5 archive files, leading to memory corruption and the instability of the application or even the entire system.

Security researcher Jaroslav Lobačevski brought this critical issue, also known as GHSL-2025-058, to light.

The technical root cause lies in a miscalculation within the RAR5 decoder’s memory operation, specifically during the My_ZeroMemory function call. When attempting to repair corrupted archive items, the decoder incorrectly calculates the amount of memory to zero out, causing it to write data beyond allocated buffer boundaries. The severity of this overflow is influenced by attacker-controlled data from preceding archive items, making it particularly dangerous.

While this vulnerability primarily leads to denial-of-service attacks rather than arbitrary code execution, its impact is still substantial. The heap buffer overflow consistently overwrites memory locations with zeros when 7-Zip processes a malicious RAR5 file. This reliability in crashing the application and potentially the system makes it a potent tool for disruption, even if it doesn’t allow for direct code execution.

Testing has confirmed that both ASAN-compiled and official Windows builds of 7-Zip are affected.

The responsible disclosure process for this vulnerability was diligently followed. The issue was privately reported on April 24, 2025, and the 7-Zip development team promptly acknowledged it within five days. A successful fix was developed and subsequently released in 7-Zip version 25.00 on July 5, 2025, demonstrating an efficient remediation timeline of approximately two months from the initial report.

Given the critical nature of this denial-of-service vulnerability, it is imperative for all 7-Zip users to update their software immediately to version 25.00 or a later release. Furthermore, organizations should exercise extreme caution when handling RAR5 files from untrusted sources. Implementing additional security measures for archive processing workflows is also highly recommended to safeguard against potential exploitation of this and similar vulnerabilities.

Reference:

  • 7-Zip Vulnerability Allows Malicious RAR5 Archives to Crash Systems and Disrupt Operations
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityJuly 2025
ADVERTISEMENT

Related Posts

SAP Patches Critical NetWeaver Flaw

EggStreme Malware Hits Philippine Military

September 11, 2025
SAP Patches Critical NetWeaver Flaw

RatOn Malware Hits Android Banking

September 11, 2025
SAP Patches Critical NetWeaver Flaw

SAP Patches Critical NetWeaver Flaw

September 11, 2025
Unreported Domains Expose Salt Typhoon

Unreported Domains Expose Salt Typhoon

September 10, 2025
Microsoft Warns of AD DS Flaw

Microsoft Warns of AD DS Flaw

September 10, 2025
Microsoft Warns of AD DS Flaw

Hackers Exploit Adobe Commerce Bug

September 10, 2025

Latest Alerts

RatOn Malware Hits Android Banking

EggStreme Malware Hits Philippine Military

SAP Patches Critical NetWeaver Flaw

Unreported Domains Expose Salt Typhoon

Hackers Exploit Adobe Commerce Bug

Microsoft Warns of AD DS Flaw

Subscribe to our newsletter

    Latest Incidents

    DDoS Defender Hit by Massive Attack

    Vienna VA Reports Data Breach Leak

    GitHub Hack Triggers Salesloft Breach

    Nexar Dashcam Database Breached

    Wealthsimple Platform Data Breach

    Cornwell Tools Data Breach Hits 104k

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial