Targeted Zero-day Attack Against Free Tools - LHAZ(Computer Security Research - McAfee Avert Labs Blog:)

セキュメモ経由

LHAZ v1.33の脆弱性をつくZeroDay攻撃が出ているそうです。

Another exploit targeting a Japanese application is found today. This time, a free decompress tool, LHAZ v1.33, was used in a targeted attack. Maliciously crafted zip files could take advantage of an unidentified vulnerability in this tool and drops a BackDoor-CKB trojan.

Lhaz v1.33 の 0-day 欠陥を突く攻略 zip ファイルが登場。マカフィー製品では Exploit-LHAZ.a として検出する。