Cryptographic Flaws in Older 7-Zip Versions
While 7-Zip has long implemented the robust AES-256 standard, older
versions of the software and its native .7z format contain
cryptographic design weaknesses and implementation flaws. These issues
primarily involve predictable initialization vectors, a lack of
authenticated encryption, reliance on non-memory-hard key derivation
functions, and support for inherently broken legacy algorithms like
ZipCrypto.
Static and Predictable Initialization Vectors (IV)
Early versions of the 7-Zip archive format implemented AES-256 in Cipher Block Chaining (CBC) mode using a fixed Initialization Vector of zero. In CBC mode, an IV must be unpredictable and unique for every encryption operation. Using a static zero IV compromises the semantic security of the cipher, allowing an attacker to determine whether two encrypted files or archive streams share identical starting data blocks without knowing the password. Later versions mitigated this by properly generating pseudo-random IVs.
Lack of Authenticated Encryption (AEAD)
Neither legacy nor modern implementations of the .7z
format use an Authenticated Encryption with Associated Data (AEAD)
construction, such as AES-GCM, nor do they include an Encrypt-then-MAC
scheme (like HMAC-SHA-256).
Instead, 7-Zip relies on CRC-32 or SHA-256 checks applied to the unencrypted plaintext. Because the integrity check occurs after decryption, the ciphertext is malleable. Attackers with write access to the encrypted archive can manipulate ciphertext blocks (bit-flipping attacks) without detection until decompression occurs, potentially exploiting vulnerabilities in the decompression parser itself.
Key Derivation Vulnerabilities to Hardware Acceleration
7-Zip derives AES keys from user-provided passwords using repeated SHA-256 hashing (typically \(2^{19}\) or 524,288 iterations). While this iteration count raised the cost of brute-force attacks when introduced in the mid-2000s, the algorithm is not memory-hard.
Modern attack hardware—specifically GPUs, FPGAs, and ASICs—can compute SHA-256 hashes in parallel with minimal memory overhead. Without modern memory-hard alternatives such as Argon2 or scrypt, older archives protected by weak or medium-complexity passwords are vulnerable to high-speed offline cracking.
Insecure Legacy ZipCrypto Support
When creating standard .zip files rather than
.7z archives, older 7-Zip versions defaulted or readily
allowed users to select the legacy PKZIP "ZipCrypto" algorithm.
ZipCrypto is an obsolete stream cipher with known mathematical flaws.
Tools using known-plaintext attacks (such as the Biham-Kocher attack)
can recover the internal state of the cipher in minutes given minimal
uncompressed data, completely bypassing password protection.
Metadata Leakage and Memory Corruption CVEs
In older configurations where header encryption was not explicitly toggled, 7-Zip stored file names, uncompressed file sizes, and directory structures in plaintext. Additionally, multiple older releases suffered from memory corruption vulnerabilities (such as CVE-2016-2335 and CVE-2018-10115) within archive parsing modules. While not strictly mathematical cryptographic failures, these vulnerabilities allowed attackers to execute arbitrary code via malformed archive structures, bypassing encryption boundaries entirely.