No indication as yet whether the new version 18.06 has the same security problems as the older versions 18.0 thru 18.05. I expect we’ll hear from Land
[See the full post at: There’s a new version of 7-Zip]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
There’s a new version of 7-Zip
Home » Forums » Newsletter and Homepage topics » There’s a new version of 7-Zip
- This topic has 26 replies, 12 voices, and was last updated 6 years, 3 months ago.
AuthorTopicViewing 11 reply threadsAuthorReplies-
Morty
AskWoody Lounger -
anonymous
GuestJanuary 1, 2019 at 1:49 am #243453 -
anonymous
GuestJanuary 1, 2019 at 6:32 am #243475The main reason I use PeaZip is that it handles drag and drop better. It doesn’t decompress everything to a folder on my main drive and then copy that folder to the other location. Granted, this is a Windows limitation, but PeaZip at least tries to get around it. The only downside is that it doesn’t support dragging over the taskbar to open up other windows–a feature I’ve bugged them about implementing.
So I don’t know about how it handles security. That said, given that the missing security features are all compile-time issues, it would seem very possible that PeaZip turns on features that the official 7-Zip release does not.
Still, given that 7-Zip opened itself up to bug bounties, it’s possible that the developer is now taking security seriously and will enable these features. It would suck to have a bounty for a known problem, after all.
-
-
jabeattyauditor
AskWoody LoungerDecember 31, 2018 at 2:12 pm #243352I already switched to PeaZip. I guess we’ll see whether there’s any reason to go back to 7-Zip.
In my experience, 7-zip is generally faster (archive & extract) than PeaZip, and that doesn’t seem to be equipment-dependent.
1 user thanked author for this post.
-
Morty
AskWoody Lounger
anonymous
Guestch100
AskWoody_MVPDecember 31, 2018 at 3:24 pm #243367Generally speaking, for any software which offers both files, msi installers are provided for the convenience of administrators who need to use deployment methods like Group Policy or SCCM. Sometimes the deployment tools either do not support exe installers because they are interactive and are difficult to automate or simply work better with the msi installers.
For end users and for any manual installation, in general exe installers contain all the configurations that the developer intended packaged in one file and in some cases even pre-requsite files like Visual C++ runtimes, while the msi do not. There are exceptions though.
I would highly recommend for any manual installation to use the exe file and fall back on msi only if needed or if there are any issues with the exe.8 users thanked author for this post.
anonymous
GuestDecember 31, 2018 at 3:29 pm #243366anonymous
GuestDecember 31, 2018 at 3:35 pm #243368? says: thank you, again PK!
i learn something new every day, here:
https://www.ghacks.net/2009/03/23/msi-or-exe-setup/
off topic? when i update the intel bluetoof i put the download on the desktop and point the device mgr. to the .ini file…
anonymous
GuestDecember 31, 2018 at 7:39 pm #243403The ASLR has been on for a couple of releases now.
https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/
“2018-04-30 – 7-Zip 18.05 released, fixing CVE-2018-10115 and enabling ASLR on the executables.”
That would be the executibles ending in .exe or .dll but not the ones ending in .sfx as those still have reloc information stripped. However, I think the .sfx modules are only used when making a self-extracting zip file, which I never make.
3 users thanked author for this post.
-
woody
Manager -
anonymous
GuestDecember 31, 2018 at 11:38 pm #243442I think the ASLR issue was the lion’s share of the problem. And I think that the EU has now offered a bounty for security faults in 7-Zip, so I like the program going forward.
The additional step I do on Win 8.1 (release 3) is to add the following mitigation options.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\7zFM.exe
QWORD MitigationOptions = 10101111311
Third from the right is a “3”. That controls the ASLR with the strictest option. Other digits in this mitigation also triggers Control Flow Guard, because unlike ASLR, there is no need for wall-to-wall CFG for it to work in those modules (Microsoft dlls) where it is compiled into.
Don’t know what to say about Win 10 because they merged EMET into the mitigation options, so half of the mitigations is QWORD, half Binary. If I had that system, I’d use the GUI to slap on some more mitigations starting with Control Flow Guard.
On Win 8.1, I’m happy with the program, and with the bounty option, expect to be happier going forward, as the author of 7-Zip will now receive reinforcements in keeping the program secure.
(Win 7 – only the right 5 “11311” mitigations are available.)
3 users thanked author for this post.
-
anonymous
GuestJanuary 1, 2019 at 9:30 am #243495In post 243426 just above , @woody says
Yep, I saw that, but I don’t think it absolves 7-Zip entirely. Unless I missed something….
@Woody , in the same article you’re talking about having seen, in the section titled “##On Exploit Mitigation” landave talks about the ASLR issues with 7-Zip that have dated back to January, when Igor seemed to flatly refuse to enable ASLR for 7-Zip. He mentions that Igor implemented ASLR in most of the .dll’s for 7-Zip, but didn’t implement it for the actual executables. This is the subject of the first two paragraphs of that section.In the third paragraph, landave says “Obviously, ASLR can only be effective if all modules are properly randomized. I discussed this with Igor and convinced him to ship the main executables of the new 7-Zip 18.05 with /DYNAMICBASE and relocation table. The 64-bit version still runs with the standard non-high entropy ASLR (presumably because the image base is smaller than 4GB), but this is a minor issue that can be addressed in a future release.”
I added the emphasis at the end of the quote above. Just maybe the referenced “minor issue” above has been addressed with this latest version of 18.06?I’m thinkin’ that third paragraph might be what ya “missed”??? 😉
1 user thanked author for this post.
-
Morty
AskWoody Lounger
-
rc primak
AskWoody_MVPJanuary 1, 2019 at 7:56 am #243486From the Release Notes at the 7-ZIP official site:
“The bug in 7-Zip 18.02-18.05 was fixed: there was memory leak in xz decoder.”
https://www.7-zip.org/history.txt
Is this the CVE cited before, and the subject of this AskWoody post? So far, nothing from Landave’s Blog about this.
As for PeaZip, which is mentioned in this thread, it has not been updated. It is still at the security level of 7-ZIP 18.05, and has not received an update since October, 2018:
http://www.peazip.org/changelog.html#latest_software_release
-- rc primak
anonymous
GuestDecember 31, 2018 at 8:56 pm #243415I bought and installed PowerArchiever years ago. What I dont like was the program installed like 100 file .extensions into my registry and they couldnt even remove those file associations.
Does 7-Zip also install a bunch of file associations, needed or not?
I dont want all those in my Windows 10 Pro set up.
-
anonymous
Guest
honx
AskWoody LoungerJanuary 1, 2019 at 2:11 am #243455as i first tried installing 7-zip 18.06 using msi installer it wanted me to kill explorer task (pid 4002), as it was “in use”, in order to be able to install. i did not do that, i did not kill explorer task, instead i aborted installation of 7-zip. in second try installation was finished without having to kill explorer task… this request about killing explorer task was gone on second try. what was it in the first place?
PC: Windows 7 Ultimate, 64bit, Group B
Notebook: Windows 8.1, 64bit, Group B-
rc primak
AskWoody_MVPJanuary 1, 2019 at 8:03 am #243487Explorer Task usually means there was an application or file system (File Explorer) window open (perhaps minimized or in the background) at the time the install was attempted. Ending this task also forces the window to close. But this way of ending an Explorer Task can render an application or even all of Windows unstable, so it is not recommended to use this method.
Either check your taskbar for minimized windows, or else log out and start fresh with a new Windows session. Check the Notification (System Tray) area for automatic tasks icons, and close these if possible, except for antivirus activities.
I often log out before installing anything if Edge or IE has been active. Even Chrome tends to leave some background processes running even when supposedly “closed”. Windows Store Apps also don’t really close when they are “closed”. They continue to run (and send “telemetry”) in the background. Sort of like on an Android or iOS phone.
-- rc primak
-
anonymous
GuestJanuary 1, 2019 at 3:08 pm #243525The dll files that ship with 7-Zip provide “context” menus when a file is right-clicked in explorer. There is two explorer modes, one that provides the shell, an another mode that operates as a file manager. Probably a dll file to be replaced was in use, or seen as being in use by the installer.
abbodi86
AskWoody_MVPSAS@HA
AskWoody LoungerJanuary 2, 2019 at 12:52 pm #243703I wasn’t aware of all of this ‘drama’. Makes the developer sound like someone you wouldn’t want to work with. There’s really no excuse for not enabling security features. Especially if the developer just wants bragging rights to say, “My installer is smaller than yours.”
For what it’s worth, I’ve disabled the context menus. I noticed that you have to Run as Admin to be able to turn them off.
PerthMike
AskWoody PlusJanuary 3, 2019 at 8:15 pm #244032Really doesn’t help when other vendors are using 7Zip in their products, and a known vulnerable old version at that. For example, I just noticed yesterday that Adobe’s Creative Cloud uses a 7Zip version 16.04 executable in its updater engine (look for 7ZA.exe).
No matter where you go, there you are.
-
mn–
AskWoody LoungerJanuary 4, 2019 at 12:42 am #244051Then again, 7za.exe is supposed to be a reduced-capability version with less attack surface. Like the RAR format specific problems, well, 7za.exe doesn’t do RAR anyway. It’s also supposed to not load DLLs I think?
Not saying that it’s necessarily safe, but at least less unsafe than the full version.
Oh well, I’d also hope that a thing like Adobe’s updater would verify package signatures before the unpacking step…
Viewing 11 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
3 hours, 44 minutes ago -
AI slop
by
Susan Bradley
2 hours, 55 minutes ago -
Chrome : Using AI with Enhanced Protection mode
by
Alex5723
5 hours, 1 minute ago -
Two blank icons
by
CR2
11 hours, 31 minutes ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
13 hours, 55 minutes ago -
End of 10
by
Alex5723
16 hours, 36 minutes ago -
End Of 10 : Move to Linux
by
Alex5723
17 hours, 5 minutes ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
13 hours, 33 minutes ago -
test post
by
gtd12345
22 hours, 36 minutes ago -
Privacy and the Real ID
by
Susan Bradley
12 hours, 44 minutes ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
4 hours, 50 minutes ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
1 day, 2 hours ago -
Upgrading from Win 10
by
WSjcgc50
4 hours, 19 minutes ago -
USB webcam / microphone missing after KB5050009 update
by
WSlloydkuhnle
22 hours, 3 minutes ago -
TeleMessage, a modified Signal clone used by US government has been hacked
by
Alex5723
1 day, 18 hours ago -
The story of Windows Longhorn
by
Cybertooth
1 day, 6 hours ago -
Red x next to folder on OneDrive iPadOS
by
dmt_3904
1 day, 20 hours ago -
Are manuals extinct?
by
Susan Bradley
8 hours, 3 minutes ago -
Canonical ditching Sudo for Rust Sudo -rs starting with Ubuntu
by
Alex5723
2 days, 5 hours ago -
Network Issue
by
Casey H
1 day, 16 hours ago -
Fedora Linux is now an official WSL distro
by
Alex5723
2 days, 17 hours ago -
May 2025 Office non-Security updates
by
PKCano
2 days, 18 hours ago -
Windows 10 filehistory including onedrive folder
by
Steve Bondy
2 days, 20 hours ago -
pages print on restart (Win 11 23H2)
by
cyraxote
1 day, 20 hours ago -
Windows 11 Insider Preview build 26200.5581 released to DEV
by
joep517
2 days, 22 hours ago -
Windows 11 Insider Preview build 26120.3950 (24H2) released to BETA
by
joep517
2 days, 22 hours ago -
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
3 days, 5 hours ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
1 day, 22 hours ago -
Asking Again here (New User and Fast change only backups)
by
thymej
3 days, 17 hours ago -
How much I spent on the Mac mini
by
Will Fastie
1 day ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.