7-Zip up to 21.07 on Windows allows privilege escalation and command execution
github.com
github.com
Logically, if there was a way to escalate privileges via 7-zip, then it could also be exploited with CreateRemoteThread() - why would a heap overflow be necessary? What change to 7-zip has he requested that would prevent that? Why the bizarre drag-and-dropping operation, why not just double click a HTA file?
I suspect there is no heap overflow and no privilege escalation.
This is just speculation, but the privesc vulnerability might be related to memory allocation in the DLL used to integrate with the system shell context menu - i.e. right clicking on a file. Just a guess based on the mention of a heap overflow.
edit: I personally think the author did a great job finding & publishing it.
Not really.
They seem to be implying they got to running a command as SYSTEM from 7-zip, but, like, don't specify things like what security context 7-zip started as, or how a program running as non-admin got to a system security context, or like, how that's 7zip's fault and not the fault of the OS.
This is all very confusing.
Even if all they did was took that screen shot from process explorer and expanded it to include the user column, it would be like 99% more clear what the fuck is going on.
"Due to community security, it will not be published until the update is passed. Maybe it will never be published :)"
would hardly call this publishing
2. "You have to update 7zip to open this archive, you don't need to open any executables, just drag 7zipv0.99.7z to help window"
3. ????
4. Profit
1) a command execution vulnerability in 7z. This is problematic because a downloaded 7z file could compromise your machine;
2) a privilege escalation vulnerability in the MS help viewer. This is problematic because it could allow an unprivileged user to gain admin rights. Why the help viewer does anything as NT AUTHORITY\SYSTEM is beyond me.
However the post presents them as one single vulnerability?
I don't get it either. From poking around in Process Explorer the help viewer window isn't its own process, it's still part of "7zFM.exe" which is running at medium integrity (not admin). Don't know where the high integrity context is coming from.
I wonder if it's silent elevation, in which case just putting UAC on "always ask" is good enough (and what I do anyway).
Given that, I think this is better removed from any system.
If you have to access .chm files, I would first try other tools for displaying html help (https://blog.kowalczyk.info/articles/chm-reader-viewer-for-w... has a list)
Even Free Pascal and Lazarus that use their own tools to both produce and view CHM files (Lazarus has its own cross-platform CHM implementation) have their own CHM files working better with the Microsoft CHM viewer than their own viewer.
It seems kind of weird, like on top of the technical details it is describing some still-in-progress argument with the 7zip folks about who is responsible for the bug.
I don't think it does. The report states that they achieved execution as NT AUTHORITY\SYSTEM using psexec from "SysInternals"; arguably, running something as SYSTEM is psexec's entire purpose, but it does require the installation of a service that runs as SYSTEM and brokers execution.
[1]: https://docs.microsoft.com/en-us/windows/win32/api/htmlhelp/...
If there is a privilege escalation vulnerability in Windows Help Viever then nobody can stop anyone from writing a payload that mimicks the heap overflowing code in 7zip.
But of course that doesn't get you clicks so why not bait everyone by attaching name of a popular open source software to it.
Torvalds was spot on about security researchers.
The description of the bug seems a bit weird
> At this stage, 7-zip stated that the vulnerability was caused by hh.exe, but they were told that if there was a command injection from hh.exe, a child process should be created under hh.exe, so especially the heap-overflow side of this vulnerability will not be shared with the community.
I think this is a reference to a conversation with the people behind 7-zip (?). It seems like a weird mix of technical details and finger-pointing.
> As it is known, Microsoft HELPER ie hh.exe file "html help. full name microsoft html help executable. Program that opens help files with the chm extension." has been defined as. Many operations such as XXE, Command Execution are performed through the hh.exe file. It is possible to see vulnerabilities such as XXE or command execution in every program that uses the hh.exe interface. This issue came to my mind after the discovery of the XXE vulnerability detected by WinRAR. (https://www.exploit-db.com/exploits/47526) Although the developers of 7-zip say that Microsoft should fix the command execution authority obtained from hh.exe at this point, it has been observed that at the end of the day, thanks to the heap overflow in 7zFM.exe and the command execution feature in hh.exe, privilege elevation is provided in the administrator mode.
Seems like a pretty solid argument from the 7zip folks, right? They can't really be blamed if the Windows help system has decided to give them root for some reason. And since 7zip is partially open source, any would-be hacker could just grab an old version of the code if they wanted to weaponize this, right?
But maybe there's something I'm missing.
The culprit is usually the insane Windows ACL permission system. Unix permissions look like "rwxr-xr-x" while a very simple example of a Windows permission is:
D:(A;OICI;FA;;;SY)(A;OICI;FA;;;WD)
Windows is a single user OS. If you are depending on its local user permission access control to be anything more than advisory you are going to have a bad time.
1. If we're talking about desktops systems, privesc is trivial in either OS. In Linux you can do a million things to privesc, such as snooping passwords via X11, modifying the various user files like ~/.bashrc with aliases, etc. On Windows UAC isn't even intended to be a barrier.
2. If we're talking about servers, I'm not sure that Windows is 10:1 worse on privescs.
On the flipside, all it takes to manipulate sudo on Unix systems is to write a TTY emulator that just middlewares between the user and sudo. Then just alias via bashrc or any number of other places that can prompt for a user password. There is not protection sudo can deploy against that. Polkit helps a bit but X11 isn't great at helping there either since other programs can just send keystrokes.
CVE database is pretty much alike.
While your last paragraph is technically true, ACLs can also be applied on files from network shares.
And of course (just as on Linux), even on single, non-networked machines, only very technical users will realistically be able to access files they are not authorised for.
Windows is not a single-user OS. Even a standard "desktop" installation can support multiple sessions through terminal services, but usually it is not configured to allow multiple concurrent interactive sessions.
I wonder how many programs have this bug? How many programs have Windows help and involve dragging and dropping files?
details on the LPE are not yet released, it's only shown in the video.
assuming the LPE is real and also caused by 7-zip, this is a critical issue for anyone that has unprivileged users use their systems where 7-zip is installed.
[1]: https://www.bleepingcomputer.com/news/security/razer-bug-let...
It wasn't even modified after the AES implementation was found to be somewhat lacking.
https://sourceforge.net/p/sevenzip/bugs/2176/
https://piunikaweb.com/2019/02/01/insecure-aes-crypto-implem...
This has a CVE number allocated (CVE-2022-29072) and the README mentions 7-zip disputing that this is their problem (rather, some underlying Windows component).
They say, form K7804? But your child, and that sounds like a lot of work to help you.. will you pay me to waste my time to help you?
You say, no guarantees that I'll pay you but if you don't inform me responsibly, I'll tell everyone you are the bad person here.
This is Microsoft's bug that affects many programs. Was Microsoft informed before this exploit was made public? What does it buy anyone to throw this out in the public first? There is no indication that the exploit finder was hunting a bounty or denied a bounty. Afaict you fabricated a controversial story in your head then tried to explain it to everyone else.
And also, disclosure actually makes attackers aware of the vulnerability. So, it is like informing a radio station which will broadcast out the message. And while many bus drivers listen to this ratio station, it is actually really popular among a set of people who enjoy crashing into misconfigured buses like this to cause mayhem.
I'm not sure how to fit the state sponsored bus crashers into the analogy. Actually I'm beginning to think it isn't a very useful analogy at all.