7-zip vulnerability gives hackers the keys to the kingdom

A threat actor could abuse the popular archiving app, 7-zip and gain elevated privileges on a device to which they already have access.

A GitHub user going by the name Kagancapar discovered a zero-day vulnerability in 7-zip for the Windows operating system (OS). The findings, posted on GitHub, revealed that, “Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area.”

Source