Moneycontrol PRO
HomeTechnologyGovernment issues security alert for Windows users over security flaw in file compressor tool: Here's what you need to do

Government issues security alert for Windows users over security flaw in file compressor tool: Here's what you need to do

India’s cybersecurity agency has warned Windows users about vulnerabilities in a popular file compressor tool that could allow remote attacks. Users should update immediately, verify sources, and avoid opening archives from unknown senders.

August 13, 2025 / 14:08 IST
Windows laptop

India’s cybersecurity agency has issued a security advisory for a widely used file size compressor tool installed on millions of Windows PCs and laptops. The alert warns about critical vulnerabilities that could allow attackers to execute malicious code, install malware, or gain unauthorized access if the tool is outdated or compromised. Users have been advised to update immediately, download only from official sources, and avoid opening compressed archives from untrusted senders.

Warning details
According to the advisory, the vulnerabilities fall under the category of remote code execution and arbitrary file write. Attackers can craft malicious archive files — including .zip, .rar, or .7z formats — that exploit flaws in the tool’s parsing or extraction routines. Simply opening or extracting such a file can trigger the exploit.

The risk is significant due to the widespread use of the software in workplaces, schools, and personal computers for routine compression tasks. Distribution of malicious archives through email attachments, messaging apps, and free download portals increases the likelihood of exploitation.

The government notes several indicators of potential threats, such as unexpected archive files from unknown sources, archives prompting scripts or installers during extraction, and requests for elevated privileges. Older builds of the tool are most at risk, and even new installations can be unsafe if downloaded from fake websites or third-party mirrors.

Malicious archives may also use deceptive techniques like double extensions (e.g., document.pdf.exe) or hiding payloads inside nested folders.

What users should do
• Update immediately: Check the tool’s version and install the latest stable release from the official developer’s website or the Microsoft Store.
• Verify authenticity: Use checksums or digital signatures where provided. Avoid downloading from freeware portals.
• Strengthen Windows security: Keep Microsoft Defender or other antivirus software updated, enable SmartScreen, and turn on Controlled Folder Access.
• Handle archives cautiously: Do not extract unsolicited files. Scan archives first, preview contents, and extract to a non-system folder without admin rights. Avoid running executables directly from archives.
• For enterprises: Implement application allow-listing, block outdated versions via endpoint management, and monitor for suspicious extraction activity.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Aug 13, 2025 02:07 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347