7-Zip Console

A heap-based-overflow was found in 7-Zip before 16.00. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed HFS+ image. *Arbitrary code execution vulnerability in 7-Zip. This is reported by Kaspersky.

*Trying to remove/ replace this with an updated version that is not vulnerable. It seem 7-Zip is embedded in the operating system, since it does not appear in programs and features.

Running Windows 7 Home/ 64 bit. How do I fix this problem?

windows 10

2 people found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Win 10 is not a solution. I am running win 10 Pro and this vulnerability still exists. When will there be a resolution to this problem? Need some help here, I don't want to risk my system because of compressing or decompressing a file. How can we(users) fix this?

Now it's three months gone by since I asked for assistance. Yikes!

3 people found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Update your version of 7-zip.  That vulnerability was "before [version] 16.00."  7-zip is now at version 16.04.

http://7-zip.org/

-----
LemP
Volunteer Moderator
MS MVP (Windows Desktop Experience) 2006-2009
Microsoft Community Contributor (MCC) 2011-2012

1 person found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Not sure how to do that. f I download and install the updated version, will it override/replace the old version? I don't see 7-zip in programs and features, so I guess it is part of the OS. A little more help/info please.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

If you don't see 7-zip in Programs and Features, then you don't have it.

Windows 7 has a native compression and extraction utility for *.zip files.  You use this from the right-click context menu:  (Send to > Compressed (zipped) folder) and (Extract all).  The functionality is in one or more DLL files (Zipfldr.dll and LZ32.DLL).  I'm not positive, but I strongly suspect that whatever the bug was in 7-zip that is the basis for the vulnerability you mentioned, it is not present in any of the Windows DLL files.  I certainly have not seen any suggestion to the contrary.

7-zip is a third-party compression/decompression utility.  It is much more versatile than the native Windows utility: 

  • Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM
  • Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RAR, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z.

7-zip also compresses files a bit more than the Windows utility.  See http://www.online-tech-tips.com/software-reviews/7-zip-vs-winzip-vs-winrar/

If you want 7-zip, get it here: http://7-zip.org/ (and if you do actually have an older version, the new version will overwrite the old one).  You can find out a bit more about 7-zip here: http://7-zip.org/faq.html

-----
LemP
Volunteer Moderator
MS MVP (Windows Desktop Experience) 2006-2009
Microsoft Community Contributor (MCC) 2011-2012

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

OK, thank you for that extra info.

Here's my mystery, when I ran the Kaspersky vulnerability scan after a Win 10 Pro upgrade, the 7-zip vulnerability came up again!

Downloaded the 1604 v. Am installing that and then I will run the KTS scan again. We'll see what happens.

I see that my Win 10 version is 1607. Is there a more recent version I should be running? I don't know if that could be an issue or not.

Trying to get up or keep up to speed with Microsoft's future for us. Learning as I go.

Thank you for your assistance. 

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I have no idea what Kaspersky would have indicated an issue with 7-zip if 7-zip was not installed.

I have rather determinedly kept away from Windows 10, but AFAIK, the latest build is the "Windows 10 Creators Update," also known as version 1703.  Because this is being "rolled out in phases" starting April 11, your system may not have received the update yet.  See

https://technet.microsoft.com/en-us/windows/release-info.aspx?f=255&MSPPError=-2147217396

https://blogs.windows.com/windowsexperience/2017/04/11/how-to-get-the-windows-10-creators-update/#7OI67R35v8qHXzRh.97

Read at least this one:

http://www.infoworld.com/article/3169615/microsoft-windows/what-you-need-to-know-about-windows-10-versions-and-lifespan.html

-----
LemP
Volunteer Moderator
MS MVP (Windows Desktop Experience) 2006-2009
Microsoft Community Contributor (MCC) 2011-2012

5 people found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

 
 

Question Info


Last updated March 12, 2024 Views 4,682 Applies to: