Skip to content
Auto-CTI
Back to today
MEDIUM A3

7-Zip: Vulnerability allows code execution

A BSI Warn- und Informationsdienst (WID): Schwachstellen-Informationen (Bürger Cert) ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The vulnerability requires user interaction and affects widely used compression software installed in many corporate environments; a CVE ID is not yet available.

Description

A vulnerability exists in 7-Zip caused by a heap-based buffer overflow when processing XZ chunked data. A remote, anonymous attacker can exploit this to execute arbitrary code. Successful exploitation requires user interaction, such as opening a manipulated archive file. No CVE ID is currently available, and there are no indications of active exploitation or inclusion in KEV catalogs.

Risk score

0
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
57.00
vendor mismatch penalty
0.00

Path: operational

ESC