Skip to main content

Zip Slip Vulnerability

Researchers have discovered a vulnerability that can be exploited to perform a directory traversal attack when a malicious archive file is extracted.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Researchers have discovered a vulnerability that can be exploited to perform a directory traversal attack when a malicious archive file is extracted.

Threat details

The vulnerability is widespread across multiple ecosystems, but is particularly prevalent in Java programs because Java does not have a central library for high level processing of archives. Popular archive utilities such as WinRAR and 7-Zip are not thought to be affected at the time of publication.

Programs are affected if they use extraction methods which do not validate filenames containing traversal sequences. When these files are extracted from archives they are not written to the target directory but are instead written to a different location in the file system.

The traversal can be exploited to overwrite files wherever the user has write permissions. An attacker can achieve remote code execution if an executable file is overwritten and the user or system then runs that file.


Remediation steps

Type Step
  • Ensure any software that extracts archive files is kept up to date.
  • Seek advice from vendors of such software if it is not clear whether their products are affected.
  • For any such software that is developed in-house, follow the suggested guidance from the researchers to check whether it is affected: snyk.io/research/zip-slip-vulnerability#what-action-should-you-take

Last edited: 17 February 2020 12:58 pm