A zero-day vulnerability has been discovered in the popular free 7-Zip app used to compress and decompress files. The vulnerability affects the Windows version of 7-Zip and allows an attacker with access to your computer to gain administrative privileges by dropping a specially-crafted .7z file on
the 7-Zip Help window.
As there is currently no patch available from 7-Zip, please do the following to prevent a possible exploitation:
1. delete or rename the 7.zip.chm file located in C:\Program Files\7-Zip
-or-
2. Ensure that 7-Zip only has read and run permissions for all users.