Menu

#387 Propagate Mark of the Web from archives to extracted files

open
nobody
None
5
2022-05-13
2022-05-13
Ben Faull
No

This patch changes Mark of the Web (Zone.Identifier ADS) propagation logic to happen for all archive extractions, instead of just when using the File Manager.

Mark of the Web is a Windows security feature that adds metadata to stamp files as originating from the internet (or an intranet), which can be used by applications to distrust files. Some example consumers of Mark of the Web are SmartScreen for executables, Microsoft Office for documents, Microsoft HTML Help for chm files, and Microsoft Visual Studio for project files.

When archive software like 7-Zip doesn't propagate Mark of the Web metadata from archives to their extracted files, attackers abuse this to bypass Mark of the Web protections by archiving their malicious files. Other popular archive software including the Windows Explorer built-in ZIP handler and WinRAR support propagating Mark of the Web to extracted files, and with this patch 7-Zip users will have the same protection.

1 Attachments

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.