First published: Fri Apr 15 2022(Updated: )
** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
7-Zip 7-Zip | <=21.07 | |
Microsoft Windows | ||
All of | ||
7-Zip 7-Zip | <=21.07 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29072 is a vulnerability in 7-Zip through 21.07 on Windows that allows privilege escalation and command execution.
CVE-2022-29072 occurs when a file with the .7z extension is dragged to the Help>Contents area in 7-Zip due to misconfiguration of 7z.dll and a heap overflow.
CVE-2022-29072 has a severity rating of 7.8, which is considered high.
7-Zip versions up to and including 21.07 on Windows are affected by CVE-2022-29072.
To fix CVE-2022-29072, it is recommended to update to a version of 7-Zip that is higher than 21.07 when available.