First published: Mon May 22 2017(Updated: )
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE ZXR10 9908 | <=16.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-7804 is considered to be high due to the potential for privilege escalation by remote attackers.
To fix CVE-2016-7804, update to version 16.03 or later of 7-Zip to eliminate the untrusted search path vulnerability.
CVE-2016-7804 can be exploited by attackers using Trojan horse DLLs placed in unspecified directories to gain privileges.
CVE-2016-7804 affects 7-Zip versions 16.02 and earlier on Windows.
No, CVE-2016-7804 has been addressed in versions 16.03 and later of 7-Zip.