7-zip vulnerability exposes code execution risk in millions of systems
TL;DR. A critical 8.8 CVE-rated vulnerability in 7-zip allows malicious code execution upon opening crafted archives with specific memory conditions. - The flaw affects all prior 7-zip versions, including command-line interfaces across multiple operating systems. - Hundreds of millions of machines are potentially vulnerable due to widespread 7-zip usage in Windows, Linux, and CI/CD workflows. - Users must immediately update to version 26.01 to mitigate the severe code execution threat.
- 7-zip contains an 8.8 CVE-rated vulnerability allowing code execution by opening a specially crafted archive.
- The vulnerability affects all 7-zip versions prior to 26.01, including command-line variants and those used in CI/CD pipelines.
- Millions of Windows, Linux, and virtual machines in data centers are at risk due to the widespread deployment of 7-zip.
- Exploitation requires a machine with at least 16 GB of RAM; extraction of the archive is not necessary.
- Users are urged to update 7-zip immediately to version 26.01 to patch the security flaw.