Reminder: 7-Zip & MoW, (Mon, Feb 10th)
这篇文章讨论了7-zip中的一个漏洞(CVE-2025-0411),指出其默认配置下未正确传播Mark-of-Web (MoW),导致嵌套ZIP文件中的文件无法继承外层ZIP的MoW标记。作者强调需手动启用此功能以提高安全性。 2025-2-10 07:27:53 Author: isc.sans.edu(查看原文) 阅读量:12 收藏

CVE-2025-0411 is a vulnerability in 7-zip that has been reported to be exploited in recent attacks. The problem is that Mark-of-Web (MoW) isn't propagated correctly: when extracted, a file inside a ZIP file inside another ZIP file will not have the MoW propagated from the outer ZIP file.

That's good to know, but what I personally consider more important to know, is that MoW isn't propagated at all by 7-zip in its default configuration.

I wrote about this a couple years ago in diary entry "7-Zip & MoW", when this new feature was introduced.

You have to enable MoW propagation in the GUI or via the registry. And that is still the case with the latest versions of 7-zip.

Didier Stevens
Senior handler
blog.DidierStevens.com


文章来源: https://isc.sans.edu/diary/rss/31668
如有侵权请联系:admin#unsafe.sh