7-Zip fixes code execution flaw triggered by opening a crafted archive
7-Zip has released version 26.02 to fix a remote code execution vulnerability that can be triggered when a user opens a specially crafted compressed file. The archiving tool is installed on a very large number of Windows systems and is routinely used to open attachments and downloads, so a flaw that fires on opening an archive is attractive to attackers who rely on phishing. There are no reports of active exploitation so far. Similar archiving tool flaws have been weaponized quickly in the past: a WinRAR vulnerability was used last year by a Russian group in phishing attacks to install malware, so patching early matters.
- Check
- Update 7-Zip to version 26.02 across workstations and servers, including copies bundled inside other software or installed manually outside your patch management system.
- Affected
- Anyone running 7-Zip before version 26.02; opening a malicious archive received by email or download can lead to code execution, a pattern attackers have abused in past archiving tool flaws.
- Fix
- Install 7-Zip 26.02, inventory manually installed copies that patch tooling may miss, and remind users to treat unexpected archive attachments with caution since opening one can be enough.