Worrying Windows security issue patched by 7-Zip, so patch now

A computer being guarded by cybersecurity.
(Image credit: iStock)

  • Security researchers warned about a vulnerability in older versions of 7-Zip
  • The vulnerability allowed threat actors to bypass the Mark of the Web security feature
  • The bug was fixed in late November 2024

A high-severity vulnerability was recently discovered, and patched, in the popular open source file archiver solution 7-Zip. Since the product does not have an automatic update feature, users are advised to upgrade to the newest version manually, as soon as possible.

The vulnerability in question is tracked as CVE-2025-0411. It is described as a Mark of the Web (MotW) bypass, that allows threat actors to execute malicious code on target endpoints that are extracting files from nested archives. It was given a severity score of 7/10 - high.

Mark of the Web is a security feature in Windows that flags files downloaded from the internet as potentially unsafe by adding metadata indicating their origin. This helps prevent malicious scripts or executables from running automatically, prompting users to confirm before opening such files.

Patching the flaw

7-Zip added support for MotW in June 2022, in version 22.00. However, the feature was improperly implemented, and could be bypassed. In a recently released advisory, cybersecurity researchers Trend Micro explain:

"This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file," the researchers said.

"The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user."

The bug has since been mitigated, with a version 24.09 being released in late November 2024.

"7-Zip File Manager didn't propagate Zone.Identifier stream for extracted files from nested archives (if there is open archive inside another open archive)," the project’s developer, Igor Pavlov, explained.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
email
A Windows filetype update may have complicated cyber threat detection efforts
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
Security padlock in circuit board, digital encryption concept
An alleged 7-Zip zero-day is actually an AI hoax
Avast cybersecurity
An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)