CVE-2017-2107: High severity 7-zip vulnerability
Published Apr 28, 2017
·Updated
Untrusted search path vulnerability in Self-extracting archive files created by 7-ZIP32.DLL 9.22.00.01 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
Akky 7-zip32.dll<=9.22.00.01
Event History
Apr 28, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2107?
CVE-2017-2107 is considered to be a high-severity vulnerability due to the potential for privilege escalation by remote attackers.
2
How do I fix CVE-2017-2107?
To fix CVE-2017-2107, upgrade to a version of 7-ZIP32.DLL later than 9.22.00.01.
3
What software is affected by CVE-2017-2107?
CVE-2017-2107 affects Self-extracting archive files created by 7-ZIP32.DLL version 9.22.00.01 and earlier.
4
Can CVE-2017-2107 be exploited remotely?
Yes, CVE-2017-2107 can be exploited remotely through the execution of malicious DLL files.
5
What kind of attacks can leverage CVE-2017-2107?
CVE-2017-2107 can be leveraged in attacks that involve the installation of Trojan horse DLL files to gain elevated privileges.