CVE-2022-29072 describes a privilege escalation and command execution vulnerability in 7-Zip through version 21.07 on Windows, affecting 7-Zip and Microsoft Windows installations utilizing it. The vulnerability, rated High severity (CVSS 7.8), stems from a misconfiguration in 7z.dll and a heap overflow, allowing an attacker to execute commands in a child process when a .7z file is dragged to the Help>Contents area. Despite the high CVSS score, multiple third parties dispute the privilege escalation claim, and there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered significant community discussion, indicating notable attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 21.07CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.