Symptoms
When installing the latest version of 7-Zip, vulnerability scans still report that older versions are installed and vulnerable.
Cause
The 7-Zip installer does not actively remove registry keys from older versions. The vulnerability is a false positive since the executable has been upgraded, but the registry keys from those previous versions trigger the detection.
Resolution
We currently have a request posted on the 7-Zip support forum for the vendor to address this in future installers. That thread is located here:
https://sourceforge.net/p/sevenzip/discussion/45797/thread/c6f74111/
This doc will be updated as that request reaches a resolution.