Skip to main content
← Back to Demos
Archive Abuse intermediate · 15 min

Tiny ZIP bomb expanding to enormous size on extraction

Archive-handling flaws keep surfacing across the industry: this digest reports a 7-Zip vulnerability enabling code execution during extraction of crafted archive files, plus an unpatched 7-Zip RCE triggered by malicious archives. A decompression bomb weaponizes normal extraction behavior — a tiny ZIP declares far larger uncompressed sizes, exhausting memory and disk when an engine blindly inflates each entry. In this demo a small, benign expansion file shows the ratio spike without risking resources. The Archive Engine detects the mismatch between the archive's small footprint and the enormous projected decompressed volume before extraction proceeds. This early validation prevents denial-of-service style resource exhaustion at the gateway, so endpoints never face the inflated payload.

Attack Technique

Decompression bomb

MITRE ATT&CK

T1499 ↗

Platforms

linuxwindows

File Types

.zip

MetaDefender Capabilities

Archive Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---