This popular Windows utility for ZIP files has a dangerous vulnerability

Malware alert against a computer screen
(Image credit: Shutterstock)

Early versions of 7-Zip, a file compression program, are affected by a security flaw with a severity score of 7.8 out of 10.

Disclosed by Trend Micro’s Zero Day Initiative and first discovered by Trend Micro Security researcher Nicholas Zubrisky back in June of this year, the flaw affects all 7-Zip versions prior to 24.07 and allows attackers to execute code on a victim’s machine.

The current version of 7-Zip is 24.08, released on June 19, 2024. However, as the program doesn’t have automatic updates, the app itself and subsequent updates need to be manually installed to protect users.

How to stay safe

So, if you are running 7-Zip and especially a version earlier than 24.07, make sure to manually install the latest update immediately to avoid falling victim to any cyberattacks leveraging these flaws.

As always though, never open any files you didn't ask for, don’t open them when you don't recognize the sender and when you're not sure what they are. To protect yourself further, make sure you’re using the best antivirus software to keep your Windows PC safe from the latest threats.

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps.