Igor Pavlov, the developer behind my favorite zipping routine, published an important security update on Jan. 28. Description and full instructions co
[See the full post at: Get 7-Zip updated now]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Get 7-Zip updated now
Home » Forums » Newsletter and Homepage topics » Get 7-Zip updated now
- This topic has 38 replies, 11 voices, and was last updated 7 years, 3 months ago by
anonymous.
Tags: 7-Zip
AuthorTopicViewing 13 reply threadsAuthorReplies-
MikeFromMarkham
AskWoody Lounger -
anonymous
GuestJanuary 30, 2018 at 9:52 am #163164me being german user, using german version of 7-zip, might have to wait for german version of 18.01 to be available. i don’t want english 7-zip installed on my german system.
on 7-zip.de there is still 16.04 latest version. http://www.7-zip.de/download.html
1 user thanked author for this post.
-
anonymous
GuestJanuary 31, 2018 at 7:08 pm #163624Anon #163164 said:
i don’t want english 7-zip installed on my german system.The \Lang\de.txt file in the install folder of 7-zip obtained from the English website is dated 28 Jan 2018.
Between v16.xx & v18.01, I don’t see any GUI changes or new fields. And running the 7-zip EXE installer does not require any reading or user input.
If you are concerned about the security vulnerabilities disclosed in Dec 2017, you can perhaps install 7-zip from the English website, before subsequently installing the version from the German website over the English version.
If 7-zip from the English website opens with an English GUI, try changing the language at:
> Menu: Tools
> Options
> Language tab1 user thanked author for this post.
-
anonymous
Guest
-
-
-
anonymous
GuestJanuary 30, 2018 at 9:55 am #163168I seem to recall having to manually uninstall the old version(s). In other words, I believe if you run the latest installer, it will not automatically uninstall any prior versions.
This may no longer be the case but I wouldn’t know since my standard practice is to first uninstall the old 7-zip install (like I just did now!).
-
woody
Manager -
anonymous
GuestJanuary 31, 2018 at 2:09 pm #163522On my Win 7 x64, as is my usual practice for 7-zip, I installed the new version over the existing version after making sure that 7-zip isn’t running.
For 7-zip v16.04 stable & older, the installer would always prompt for a reboot. If I rebooted immediately after installation, the system would register that 7-zip had been upgraded to a new version, & reflect this accordingly at the ‘Programs & Features’ pane.
If I delayed the reboot, the system upon subsequent bootups would fail to notice that I’d installed a new version of 7-zip, even though all files in its install folder were successfully updated. And the ‘Programs & Features’ pane would continue to show the older 7-zip version.
This time round, surprisingly enough, 7-zip v18.01 stable‘s installer did not prompt for a reboot. But the new version is reflected at the ‘Programs & Features’ pane. Meanwhile, all files in 7-zip’s install folder are updated to the latest version — except for 7-zip.dll (shell extension) which remains the old version. It turns out that the installer had instead renamed the new version to 7-zip.dll.tmp.
Not sure if a reboot would’ve removed the aforementioned old DLL file. In any case, I unlocked & deleted the old DLL file, & renamed the new DLL to its rightful filename. That was almost 2 days ago, & so far, all 7-zip operations work fine.
-
-
GoneToPlaid
AskWoody LoungerJanuary 30, 2018 at 10:09 am #163172I have always gotten 7zip from the SourceForge web site which is secure. Here is the web page for the latest 7-zip version 18.01:
https://sourceforge.net/projects/sevenzip/files/7-Zip/18.01/
The above page also has 7-zip msi installers as well.
-
woody
Manager -
anonymous
Guest
-
-
-
anonymous
GuestJanuary 30, 2018 at 12:01 pm #1632077-Zip is also available on Ninite. If you already have 7-Zip installed, running the Ninite Installer for 7-Zip will update it. Quick, easy, simple, and painless; took me ten seconds to update 7-Zip with Ninite. Strongly recommend. Sanity in a world plagued by Microsoft making things complicated.
-
glnz
AskWoody Plus -
anonymous
GuestJanuary 30, 2018 at 4:14 pm #163277An .exe is a generically compiled executable file. In this case, the executable contains the installation of an application. But an .exe can be pretty much that can run on Windows.
When you install an .exe, you’ll get the stupid typical boring questions that you have to give attention to them and answer next next next next.
An .msi is an installation file for Windows. Apart from installing a program, it allows some switches to be activated, such as quiet (no output to the screen), and is more manageable for corporate environments.
Some more info:
1 user thanked author for this post.
-
satrow
AskWoody MVP -
anonymous
GuestJanuary 31, 2018 at 2:31 pm #163530glnz said:
For each of these machines, should I install the .exe or the .msi? […] What is the diff between an .exe and a .msi anyway?Since there are just 3 PCs you want to install 7-zip to, EXE installers are fine. EXE installers are generally smaller in filesize, & they can also be deployed on standalone PCs not connected to any network.
And depending on the developer, some EXE installers may come with command-line switches to allow silent unattended installation, eg. for cases where the installer comes with multiple screens requiring user input.
However, 7-zip’s EXE installer does not come with multiple screens. It’s a 1-step process (ie. click to run the installer), which copies the files to the default install folder. You may be prompted to reboot the PC to complete the installation process.
For corporate environments with multiple networked PCs, MSI installers are preferred because they allow mass deployment via Windows Group Policy.
-
-
anonymous
Guest -
Bill C.
AskWoody PlusJanuary 30, 2018 at 5:13 pm #163312I GREATLY prefer manual updating over auto anything, except AV programs.
Notifications of a new version are OK when you launch the program, as long as it lets you use the program without doing the update. Automatically checking is fine if it is frequently updated, but only if you can modify or turn the checking schedule off. I usually turn that capability off if possible.
For this program, the last update was in 2016. Why use resources to constantly check on programs not frequently updated.
This is how user control erodes.
-
-
Bill C.
AskWoody PlusJanuary 30, 2018 at 5:03 pm #163307Thanks. I updated last night when I saw it on Tweakguides.
I was going to post the info here, but there you were!
I updated over 16.04-64. After the install finished, I went to the Z-Zip folder in Program Files and all the files except 7z.dll were dated the same. There was also a file 7z.dll.tmp with the new date. I then closed file explorer, and re-opened it, the old 16.04 file had disappeared and the new 18.01 7z.dll was present.
Control Panel only shows the current version, 18.01.
-
anonymous
GuestJanuary 31, 2018 at 6:36 pm #163620Bill C. said:
After the install finished, I went to the Z-Zip folder in Program Files and all the files except 7z.dll were dated the same. There was also a file 7z.dll.tmp with the new date. I then closed file explorer, and re-opened it, the old 16.04 file had disappeared and the new 18.01 7z.dll was present.Sounds similar to my experience in upgrading from 7-zip v16.04 (x64) stable to v18.01 (x64) stable on Win 7 x64:
https://www.askwoody.com/forums/topic/get-7-zip-updated-now/#post-163522A few seconds after 7-zip installation was completed, when I tapped the Windows key to access the Start Menu, explorer.exe unexpectedly crashed. No program was running at that time.
When I went to 7-zip’s install folder, I found that 7-zip.dll (7-zip’s shell extension for context menu’s right-click) was still v16.04, alongside an extra 7-zip.dll.tmp which was v18.01. This differs from your comment vis-a-vis 7z.dll & 7z.dll .tmp — which I assume aren’t typos.
Even after I opened & closed Win Explorer a couple of times, followed by terminating & restarting the explorer.exe process twice via Task Manager, 7-zip.dll refused to get itself updated to the new version. So what I did was to unlock & delete the old 7-zip.dll, before deleting the “tmp” extension from 7-zip.dll.tmp.
Seems that the installer for recent 7-zip versions (stable & beta) might be a little buggy — in that it may fail to unlock whatever 7-zip file that was locked, before attempting to replace the old file(s) with the new ones.
And apparently, uninstallation of recent 7-zip versions may go similarly awry. On 24 Dec 2017, a user reported at the official 7-zip forum that as of beginning of Dec 2017, 7-zip.dll remains locked in 7-zip’s folder & can’t be removed, despite repeated uninstalls, re-installs & uninstalls of 7-zip. So 7-zip persists as a zombie item in his Win Explorer’s context menu. Presumably, he had rebooted the system at least once between early Dec & 24 Dec, so this issue is probably not due to a lack of reboot.
1 user thanked author for this post.
-
-
PerthMike
AskWoody PlusJanuary 30, 2018 at 6:22 pm #163328me being german user, using german version of 7-zip, might have to wait for german version of 18.01 to be available. i don’t want english 7-zip installed on my german system. on 7-zip.de there is still 16.04 latest version. http://www.7-zip.de/download.html
You seem to have no trouble using English. You speak/type it just fine.
No matter where you go, there you are.
-
GoneToPlaid
AskWoody LoungerJanuary 31, 2018 at 1:42 am #163371Hi Woody,
I read your Computerworld article about the newly discovered 7-Zip vulnerabilities. More important to me was the link in your article which described the two security holes which were found in 7-Zip. The reason I mention this is in relation to antivirus programs and the user selectable settings for scanning options. Let me explain…
Many AV programs have an option to scan within compressed files when scanning newly downloaded files, or when scanning the entire computer. The issue is that the AV program, when scanning compressed files, uses its own decompressor (or unpacker) in order to scan within compressed files. Thus, the same types of vulnerabilities which were found in how 7-Zip decompresses files may be present in the AV program’s decompressor. In fact, such flaws have been found in an AV program’s decompressor at least once in the past. This is one reason why, aside from the differences in speed when performing full scans of a computer, many AV programs have an option to either enable or disable scanning within compressed files.
Thus it boils down to just how much a user trusts their AV program’s ability to properly scan within compressed files. Does the user enable scanning within compressed files, trusting that the AV program’s decompressor doesn’t get breached in the process? Or does the user more greatly trust their AV program’s ability to detect malware when the compressed file is executed? This is very much the which came first joke — the chicken or the egg.
If the AV program’s decompressor is flawed, then malware could silently install simply when the AV program tries to scan within the compressed archive file, such as a packed EXE file. In this scenario, the EXE file was never run by the user, yet the AV program’s decompressor was breached when the AV program’s decompressor tried to scan within the packed EXE file.
On the other hand and if the AV program was configured to never scan within compressed archive files, the AV program might well indeed detect and block malicious code within the compressed EXE file when the user launches the compressed EXE file which first unpacks itself in order to run.
Like I said, it is the chicken or the egg — given the plethora of compression and packing formats which an AV program’s built-in decompressor has to know about, in order to for the AV program to be able to scan within compressed files.
-
anonymous
GuestJanuary 31, 2018 at 3:26 pm #163554GoneToPlaid said:
The issue is that the AV program, when scanning compressed files, uses its own decompressor (or unpacker) in order to scan within compressed files. Thus, the same types of vulnerabilities which were found in how 7-Zip decompresses files may be present in the AV program’s decompressor.I use MalwareBytes v1.75, which includes 7z.dll as a standalone file in its install folder. When 7-zip is updated, I always replace MalwareBytes’s copy of the DLL with the new version.
Note that the replacement 7z.dll must be 32-bit (extract it from the 32-bit EXE installer), because Malwarebytes (which is 32-bit) will refuse to run if the 64-bit DLL is used, even when the host system is 64-bit.
On a related note, for those using other file archivers such as the following …
- PeaZip uses standalone 7z.dll, 7z.exe, 7z.sfx & 7zCon.sfx. So be sure to replace with the updated binaries, as the latest version of PeaZip (v6.5.0) was released on 22 Oct 2017.
- Bandizip can create & extract 7-zip archives, but the application folder does not contain standalone 7-zip binaries. Considering that the latest version of Bandizip (v6.10) was released on 18 Sep 2017, if Bandizip does use 7-zip binaries under the hood, it may not be safe to use Bandizip for 7-zip archives.
1 user thanked author for this post.
-
Bill C.
AskWoody PlusJanuary 31, 2018 at 5:23 pm #163599I too had a program that has some 7Zip files incorporated. It was a few years ago, and I cannot remember what it was, but I was using the PSI program that checked for updates and patches. It flagged 7Zip as needing an update. I updated it, but I kept getting the warning. I finally used the feature that opened the folder with the offending file and found it was not 7Zip but the other program. I copied the new file out of the new 7Zip install to the older program. I tested if it still worked, it did, so I rescanned and the warning was gone.
-
anonymous
GuestJanuary 31, 2018 at 8:50 pm #163633Bill C. said:
I was using the PSI program that checked for updates and patches. […] I finally used the feature that opened the folder with the offending file and found it was not 7Zip but the other program.That’s great. I suppose you mean Flexera’s Secunia Personal Software Inspector ? I understand that the v3.x versions have a severely dumbed-down GUI & reduced feature-set. And the open file location function you mentioned is one of those there got removed.
https://www.ghacks.net/2012/06/28/secunia-personal-software-inspector-3-0-final-released
Features the company removed included threat ratings, detailed version and program information, as well as links to advisories and other related information.https://www.ghacks.net/2012/06/28/secunia-personal-software-inspector-3-0-final-released/#comment-1452754
Features like […] show file location and open Secunia vulnerability page will be greatly missed.The last PSI v2.x (v2.0.0.4003, released: 18 Oct 2011) is still available for download, but reached EOL as of Mar 2017. I assume this means that v2.x can no longer connect to PSI’s binary signature database.
The latest PSI is v3.0.0.11005 (released: 02 Feb 2016), but there is no changelog for this version.
1 user thanked author for this post.
-
Bill C.
AskWoody PlusFebruary 1, 2018 at 1:36 am #163674Started with v1 and then 2 on XP and used it on WIn7. I then “upgraded” to v3. I used v3 for a short time but it was aweful and would frequently hang or could not generate the report, so I went back to v2 that you cited. It worked up until mid-2017 and I uninstalled it. Looking back I find I am now far more circumspect about anything called an upgrade, thanks to GWX, etc.
I never used it as an updater for the programs or patches. I just used it to scan and then went to the flagged programs website or Windows Update for the patch or updates. Under Secunia it had a support forum and lots of tips. However with Flexara it felt like the red-headed stepchild or was treated like a houseplant left by a prior tenant when you move into an apartment and was just never watered. It still has the Forum, but it is less active. In fairness that could be good and everything is working smoothly, but I suspect teh user base is much smaller. Too bad it was a great tool.
-
-
-
anonymous
GuestFebruary 1, 2018 at 12:19 pm #163810Bandizip can create & extract 7-zip archives, but the application folder does not contain standalone 7-zip binaries.
Update: A new Bandizip v6.11 (01 Feb 2018) has just been released. The changelog mentions: “Security problem while processing archive password”, as well as “Several minor bugs fixed” amongst other things.
It is not clear if any of the listed changes are related to 7-zip. But even if not, it is still good to use the latest version, since it has at least 1 known security-related fix.
-
-
-
BobbyB
AskWoody LoungerJanuary 31, 2018 at 2:14 am #163377Should any of you be “brave” enough to be running Win10Pro V1709 and above the M$ anti-virus now has a controlled access feature in the settings if you wish to run or are having trouble running 7zip inc. the latest version here’s how to add it to prevent the annoying warnings and 7zip just plain not working.
7zip was one of the exceptionally rare free progs. aka “fluff” that came with a brand new machine that I actually liked, in fact fairly indispensible. Mainly due to its speed and multi-functionality with varying genre’s of zip files. In fact “no self respecting machine should be without one.”
-
anonymous
GuestJanuary 31, 2018 at 3:04 pm #163547According to the post by landave (who discovered & reported the vulnerabilities), ‘ZIP Shrink: Heap Buffer Overflow’ (CVE-2017-17969) was fixed in v18.00 beta (10 Jan 2018).
However, the below is what he posted regarding the other security vulnerability ‘Memory Corruptions via RAR PPMd’ (CVE-2018-5996):
I have discussed this issue with Igor Pavlov and tried to convince him to enable all three flags.
However, he refused to enable /DYNAMICBASE because he prefers to ship the binaries without relocation table to achieve a minimal binary size.
Moreover, he doesn’t want to enable /GS, because it could affect the runtime as well as the binary size.
At least he will try to enable /NXCOMPAT for the next release. Apparently, it is currently not enabled because 7-Zip is linked with an obsolete linker that doesn’t support the flag.
In other words, v18.01 stable (29 Jan 2018) may or may not include a proper for CVE-2018-5996 because:
- /NXCOMPAT — flag may or may not have been enabled
- /DYNAMICBASE — won’t fix
- /GS — won’t fix
Meanwhile, 7-zip’s changelog does not mention anything about security fixes. v18.00 beta & v18.01 stable only indicate that “Some bugs were fixed” — unless this is opaque code-speak denoting security fixes (but which ones ??).
A few days ago, landave recompiled 7-zip with the /DYNAMICBASE & /GS flags enabled, & the incurred increase in binary size is a grand total of … 8704 bytes (= 8.704 KB):
https://www.reddit.com/r/netsec/comments/7se84r/7zip_multiple_memory_corruptions_via_rar_and_zip/dt6mt2y
The relocation table is actually pretty small. I just tried to compile 7-Zip with VS2017 and /DYNAMICBASE. The main binary 7z.dll is 1,569,792 bytes in total, 9344 bytes (0.595%) of which are used by the relocation table. Enabling stack canaries (/GS) gives me a 1,578,496 byte binary (including the relocation table), so another 8704 bytes more.1 user thanked author for this post.
-
anonymous
Guest -
anonymous
GuestFebruary 1, 2018 at 2:49 pm #163846@ Anon #163823
7zxa.dll is the 7-zip standalone extracting plugin for 7z, lzma, cab, zip, gzip, bzip2, Z, & tar formats.To be on the safer side, it is better to replace it with the latest version, which at least comes with some (if not all) security fixes. The DLL is found in the “Extra” package:
- https://sourceforge.net/projects/sevenzip/files/7-Zip/18.01/7z1801-extra.7z
- (Non-HTTPS Mirror): http://www.7-zip.org/a/7z1801-extra.7z
The downloaded “Extra” package contains the said DLL as follows:
- \7zxa.dll => 32-bit
- \x64\7zxa.dll => 64-bit
Note that the package also contains the similar-looking 7za.dll & \x64\7za.dll, so be careful not to replace the wrong DLL in WinRAR’s folder.
1 user thanked author for this post.
-
anonymous
Guest
-
-
-
anonymous
GuestFebruary 1, 2018 at 9:06 pm #163915A (very non-comprehensive) list of 3rd-party applications that use 7-zip libraries:
http://www.7-zip.org/links.htmlCommon examples (including some not in 7-zip’s official list):
- SWF Player: Adobe Flash
- Installer Authoring: NSIS, Inno Setup
- File Unpackers: InnoUnp, UniExtract2
- File Compressor/Decompressor: UPX, zlib (?, I know it can decompress 7z archives)
- File Managers: Total Commander, Speed Commander. FAR Manager
- File Archivers: WinRAR, PowerArchiver, Peazip, Bandizip (?, latest: 01 Feb 2018), FreeArc
- Media Players: Foobar2000’s 7-zip plugin (foo_unpack_7z.dll)
- Some .NET applications
If the 3rd-party application is under support, check with its developer/vendor for updates.
Or if updates are not forthcoming soon, replace their 7-zip libraries if possible (ie. if the relevant files are standalone, instead of being embedded).
Malwarebytes (which uses 7z.dll) has just released a new v3.3.1.2183-1.0.262-1.0.3839 (01 Feb 2018). Installer (EXE): https://downloads.malwarebytes.com/file/mb3
As of now, the changelog does not reflect the latest point-release, but based on Malwarebytes’ 31 Jan 2018 forum comment, it appears that the release comes with updated 7-zip binaries.
Viewing 13 reply threads - This topic has 38 replies, 11 voices, and was last updated 7 years, 3 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
*Some settings are managed by your organization
by
rlowe44
4 hours, 45 minutes ago -
Formatting of “Forward”ed e-mails
by
Scott Mills
6 hours, 59 minutes ago -
SmartSwitch PC Updates will only be supported through the MS Store Going Forward
by
PL1
7 hours, 24 minutes ago -
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
16 hours, 24 minutes ago -
AI slop
by
Susan Bradley
15 hours, 35 minutes ago -
Chrome : Using AI with Enhanced Protection mode
by
Alex5723
17 hours, 41 minutes ago -
Two blank icons
by
CR2
3 hours, 15 minutes ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
1 day, 2 hours ago -
End of 10
by
Alex5723
1 day, 5 hours ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
3 hours, 10 minutes ago -
test post
by
gtd12345
1 day, 11 hours ago -
Privacy and the Real ID
by
Susan Bradley
1 day, 1 hour ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
17 hours, 30 minutes ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
1 day, 15 hours ago -
Upgrading from Win 10
by
WSjcgc50
3 hours, 20 minutes ago -
USB webcam / microphone missing after KB5050009 update
by
WSlloydkuhnle
6 hours, 53 minutes ago -
TeleMessage, a modified Signal clone used by US government has been hacked
by
Alex5723
2 days, 7 hours ago -
The story of Windows Longhorn
by
Cybertooth
1 day, 19 hours ago -
Red x next to folder on OneDrive iPadOS
by
dmt_3904
2 days, 9 hours ago -
Are manuals extinct?
by
Susan Bradley
2 hours, 56 minutes ago -
Canonical ditching Sudo for Rust Sudo -rs starting with Ubuntu
by
Alex5723
2 days, 18 hours ago -
Network Issue
by
Casey H
2 days, 5 hours ago -
Fedora Linux is now an official WSL distro
by
Alex5723
3 days, 6 hours ago -
May 2025 Office non-Security updates
by
PKCano
3 days, 6 hours ago -
Windows 10 filehistory including onedrive folder
by
Steve Bondy
3 days, 8 hours ago -
pages print on restart (Win 11 23H2)
by
cyraxote
2 days, 9 hours ago -
Windows 11 Insider Preview build 26200.5581 released to DEV
by
joep517
3 days, 10 hours ago -
Windows 11 Insider Preview build 26120.3950 (24H2) released to BETA
by
joep517
3 days, 10 hours ago -
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
3 days, 18 hours ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
3 hours, 26 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.