logo

7-Zip bug could allow a bypass of a Windows security feature. Update now

ID: 35b346e3-5420-5b92-96f3-f2f25487a7cb

STIX ID: report--35b346e3-5420-5b92-96f3-f2f25487a7cb

Feed Name: Malwarebytes Blog

Threat Score
50/100

Date Published: 2025-01-22

Date Updated: 2026-04-28

...
...

A vulnerability in 7-Zip allowed attackers to bypass Windows' Mark-of-the-Web (MotW) by placing specially crafted nested archives so that alternate data streams (which carry MotW) were not preserved when extracting files; this could cause Office documents to open outside Protected View and enable macros. The vendor released a patch in 7-Zip 24.09 and the report advises updating, enabling archive scanning in anti-malware tools, and exercising caution when opening downloaded archives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.