CVE-2018-10115 describes an incorrect initialization logic vulnerability in the RAR decoder objects of 7-Zip versions 18.03 and earlier. This flaw allows remote attackers to trigger a denial of service or potentially execute arbitrary code through a crafted RAR archive. With a CVSS score of 7.8 (High), the vulnerability requires user interaction (opening a malicious file) but has low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While not listed in CISA KEV or having public exploit code in Metasploit/Nuclei/ExploitDB, it has garnered significant community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.03CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.