CVE-2016-7804: High severity zte zxr10 9908 vulnerability
Published May 22, 2017
·Updated
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
7-Zip 7-zip Windows<=16.02
Event History
May 22, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-7804?
The severity of CVE-2016-7804 is considered to be high due to the potential for privilege escalation by remote attackers.
2
How do I fix CVE-2016-7804?
To fix CVE-2016-7804, update to version 16.03 or later of 7-Zip to eliminate the untrusted search path vulnerability.
3
What types of attacks can exploit CVE-2016-7804?
CVE-2016-7804 can be exploited by attackers using Trojan horse DLLs placed in unspecified directories to gain privileges.
4
Which versions of 7-Zip are affected by CVE-2016-7804?
CVE-2016-7804 affects 7-Zip versions 16.02 and earlier on Windows.
5
Is CVE-2016-7804 present in the latest versions of 7-Zip?
No, CVE-2016-7804 has been addressed in versions 16.03 and later of 7-Zip.