CVE-2026-58052
Published: June 28th, 2026
7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content.
LOW
CVSS v3: 3.3
CVSS v3: 3.3
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 26.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 26.2 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 26.1 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 25.4 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 25.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 25.2 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 25.1 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 24.4 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 24.4.0 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 24.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 24.2 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 24.1 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 23.3 | 7-zip (23.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 23.2 | 7-zip (17.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 23.1 | 7-zip (17.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
| 22.4 | 7-zip (17.01) | Not Affected | Code Not Present | The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific. |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
NONE
Base Score
3.3
Base Severity
LOW
Confidentiality Impact
NONE
Integrity Impact
LOW
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Version
3.1