# What Component Does the 7zip-rar5-motw-chain-poc Vulnerability Affect?

> Discover how the 7zip-rar5-motw-chain-poc vulnerability affects the 7-Zip RAR5 extraction engine. Learn about its impact on ADS and MotW handling.

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: deep-dive
- Published: 2026-09-06

---

**The 7zip-rar5-motw-chain-poc vulnerability specifically targets the 7-Zip RAR5 extraction engine, particularly its handling of alternate data streams (ADS) and Mark-of-the-Web (MotW) propagation when processing RAR5 `STM` service records.**

The `bikini/exploitarium` repository hosts this proof-of-concept which demonstrates a critical flaw in 7-Zip 26.01 on Windows. By manipulating how the extraction routine handles stream names, attackers can overwrite security markers that typically warn users about files originating from the internet.

## The Vulnerable Component

The affected component is **7-Zip's RAR5 extraction code** that processes alternate data streams during archive decompression. Specifically, the vulnerability exists in the logic that propagates Internet zone markers from the source archive to extracted files.

### RAR5 Service Record Handling

During extraction, 7-Zip processes RAR5 `STM` service records to recreate alternate data streams on the destination NTFS volume. The extraction engine treats stream names literally, allowing specially crafted archives to specify arbitrary ADS paths including `:Zone.Identifier:$DATA`.

According to the repository's [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) (lines 3-5), the PoC demonstrates a *"RAR5 alternate-stream handling issue in 7-Zip 26.01 on Windows"* that enables this manipulation.

## How the Exploit Works

### Crafting the Malicious Archive

In [`poc.py`](https://github.com/bikini/exploitarium/blob/main/poc.py), the `service_stream` function (lines 90-96) builds malicious RAR5 archives containing two critical service records:

- A `::$DATA` stream containing the visible file content
- A `:Zone.Identifier:$DATA` stream containing attacker-controlled MotW data

This construction exploits the extraction engine's failure to sanitize stream names before creating ADS entries on the destination filesystem.

### The NTFS Stream Collision

When 7-Zip extracts these archives, it propagates the `Zone.Identifier` stream from the archive alongside its own MotW marker. Because NTFS resolves both the archive-provided stream name and the propagated MotW stream to the same alternate data stream, the attacker-controlled data overwrites the legitimate security marker.

The extraction validation logic in [`poc.py`](https://github.com/bikini/exploitarium/blob/main/poc.py) (lines 86-96 and 92-95) confirms this behavior by verifying that both the visible file content and the `Zone.Identifier` ADS contain attacker-controlled values rather than the expected security warnings.

## Running the Proof of Concept

You can verify the vulnerability using the PoC script against a local 7-Zip installation:

```bash
python ./poc.py --sevenzip "C:\Program Files\7-Zip\7z.exe"

```

Successful exploitation produces output confirming the full chain:

```

[+] 7-Zip: 7-Zip 26.01 (x64) : Copyright (c) 1999-2026 Igor Pavlov : 2026-04-27
[+] archive sha256: A962DDB7A0313545521C3250EB7E01EB275F50C83DBC0466FFC94011FB4A0800
[+] final visible content: ATTACKER final visible bytes from ::$DATA stream\r\n
[+] final Zone.Identifier: [ZoneTransfer]\r\nZoneId=0\r\n
[+] VULNERABLE: full chain verified

```

## Affected Versions and Files

The vulnerability specifically impacts **7-Zip 26.01** on Windows systems. Key files in the `bikini/exploitarium` repository include:

- [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) - Contains the overview, target version, and detailed attack steps
- [`poc.py`](https://github.com/bikini/exploitarium/blob/main/poc.py) - Implements the malicious archive builder (`service_stream` function) and verification logic
- `.gitignore` - Standard ignore patterns for the PoC directory

The extraction routine's failure to isolate stream names before ADS creation represents the core weakness in the RAR5 processing engine.

## Summary

- The **7zip-rar5-motw-chain-poc** targets 7-Zip's RAR5 extraction engine, specifically the ADS handling and MotW propagation logic
- The vulnerability allows attackers to overwrite `Zone.Identifier` alternate data streams using malicious RAR5 `STM` service records
- Affected versions include **7-Zip 26.01** on Windows
- The `service_stream` function in [`poc.py`](https://github.com/bikini/exploitarium/blob/main/poc.py) demonstrates how to craft archives that exploit this stream name collision
- Successful exploitation results in extracted files appearing to originate from the local computer (ZoneId=0) rather than the internet

## Frequently Asked Questions

### What is the Mark-of-the-Web (MotW) and why does it matter?

**Mark-of-the-Web** is a Windows security feature that adds a `Zone.Identifier` alternate data stream to files downloaded from the internet. This marker triggers security warnings when users attempt to execute potentially dangerous files. By overwriting this marker, attackers can bypass Windows security prompts that would normally alert users to dangerous file origins.

### How dangerous is the 7zip-rar5-motw-chain-poc vulnerability?

This vulnerability is **highly dangerous** because it completely neutralizes a critical Windows security boundary. Attackers can deliver malware in RAR5 archives that, once extracted, appears to users and security software as originating from the local machine rather than the internet, eliminating both user warnings and automated security scanning triggers.

### Which versions of 7-Zip are affected?

According to the source code analysis, the PoC specifically targets **7-Zip 26.01** on Windows. The vulnerability relies on the specific implementation of RAR5 alternate data stream handling in this version's extraction engine.

### Can this vulnerability be exploited on non-Windows systems?

**No.** This vulnerability specifically targets the interaction between 7-Zip's RAR5 extraction logic and **NTFS alternate data streams**. Since MotW and ADS are Windows-specific features, the exploit chain only functions on Windows systems using NTFS volumes.