Tech

Worrying Windows security issue patched by 7-Zip, so patch now

Share
Share


  • Security researchers warned about a vulnerability in older versions of 7-Zip
  • The vulnerability allowed threat actors to bypass the Mark of the Web security feature
  • The bug was fixed in late November 2024

A high-severity vulnerability was recently discovered, and patched, in the popular open source file archiver solution 7-Zip. Since the product does not have an automatic update feature, users are advised to upgrade to the newest version manually, as soon as possible.

The vulnerability in question is tracked as CVE-2025-0411. It is described as a Mark of the Web (MotW) bypass, that allows threat actors to execute malicious code on target endpoints that are extracting files from nested archives. It was given a severity score of 7/10 – high.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Boeing announces .55 bn sale of some digital aviation assets to Thoma Bravo
Tech

Boeing announces $10.55 bn sale of some digital aviation assets to Thoma Bravo

Credit: Wikipedia Boeing plans to sell portions of its digital aviation solutions...

ChatGPT crosses a new AI threshold by beating the Turing test
Tech

ChatGPT crosses a new AI threshold by beating the Turing test

When ChatGPT uses the GPT-4.5 model, it can pass the Turing Test...

Tesla, hammered by protests and plummeting sales, to report 1st quarter performance
Tech

Tesla, hammered by protests and plummeting sales, to report 1st quarter performance

Tesla vehicles line a parking lot at the company’s Fremont, Calif., factory...

Volkswagen unveils its electric counter-offensive in China
Tech

Volkswagen unveils its electric counter-offensive in China

On the eve of the opening of massive industry show Auto Shanghai,...