ZDI-23-1165 (2024)

August 23rd, 2023

See Also
7z Format

7-Zip 7Z File Parsing Integer Underflow Remote Code Execution Vulnerability

ZDI-23-1165
ZDI-CAN-18588

CVE ID CVE-2023-31102
CVSS SCORE 7.8, AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AFFECTED VENDORS 7-Zip
AFFECTED PRODUCTS 7-Zip
VULNERABILITY DETAILS

This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of 7Z files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process.

ADDITIONAL DETAILS 7-Zip has issued an update to correct this vulnerability. More details can be found at:
https://sourceforge.net/p/sevenzip/discussion/45797/thread/713c8a8269/
DISCLOSURE TIMELINE
  • 2022-11-21 - Vulnerability reported to vendor
  • 2023-08-23 - Coordinated public release of advisory
CREDIT goodbyeselene

BACK TO ADVISORIES

ZDI-23-1165 (2024)

FAQs

What is the vulnerability of 7-Zip 23? ›

CVE-2023-31102 is a 7Z File Parsing Integer Underflow Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., risk is high). The Zero Day Initiative writes that this vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.

Is 7-Zip vulnerable? ›

The specific flaw exists within the parsing of 7Z files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process.

What is the 7-Zip flaw? ›

7-Zip vulnerability or CVE-2022-29072 is an active zero-day vulnerability and is characterized as allowing privilege escalation and command execution for Windows when a file with the . 7z extension is dragged to the Help > Contents area.

What is the biggest vulnerability to computer? ›

Top computer security vulnerabilities
  • Malware.
  • Phishing.
  • Proxies.
  • Spyware.
  • Adware.
  • Botnets.
  • Spam.

What is the ZIP traversal vulnerability? ›

The Zip Path Traversal vulnerability can be used to achieve arbitrary file overwrite. Depending on conditions, the impact might vary, but in many cases this vulnerability can lead to major security issues such as code execution.

What is the 7-Zip chm vulnerability? ›

This is an active zero-day vulnerability and is characterized as allowing privilege escalation and command execution. In other words, someone with limited access to your computer would be able to gain higher-level control, usually admin access, to run commands or apps.

What is PE vulnerability in 7-Zip? ›

PE vulnerability in 7-Zip

Malicious users can exploit this vulnerability to gain privileges and execute arbitrary code by dragging and dropping file with the . 7z extension to the Help>Contents area. The vulnerability announced in version 21.07 and disputed by vendor.

What is the name of the vulnerability we test for by submitting 7 * 7? ›

To check a site, http://example.com/?username=${7*7} URL can help in SSTI detection. Here, you need to replace 'example.com' with the name of the site. If the URL search result features any mathematical value, it shows the presence of SSTI vulnerability.

Top Articles
Convert $29.70 per hour to Yearly salary | Talent.com
Pag-IBIG Contributions to Double in February 2024 | Sprout Solutions
Lorton Transfer Station
فیلم رهگیر دوبله فارسی بدون سانسور نماشا
13 Easy Ways to Get Level 99 in Every Skill on RuneScape (F2P)
Kokichi's Day At The Zoo
1movierulzhd.fun Reviews | scam, legit or safe check | Scamadviser
Walgreens Alma School And Dynamite
United Dual Complete Providers
Swimgs Yung Wong Travels Sophie Koch Hits 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Springs Cow Dog Pig Hollywood Studios Beach House Flying Fun Hot Air Balloons, Riding Lessons And Bikes Pack Both Up Away The Alpha Baa Baa Twinkle
Echo & the Bunnymen - Lips Like Sugar Lyrics
Used Drum Kits Ebay
6813472639
Suffix With Pent Crossword Clue
Illinois Gun Shows 2022
Craigslist Free Stuff Santa Cruz
Edicts Of The Prime Designate
Noaa Ilx
Craigslist List Albuquerque: Your Ultimate Guide to Buying, Selling, and Finding Everything - First Republic Craigslist
Rust Belt Revival Auctions
Walgreens 8 Mile Dequindre
1 Filmy4Wap In
TMO GRC Fortworth TX | T-Mobile Community
Chelsea Hardie Leaked
Trust/Family Bank Contingency Plan
Sam's Club Near Wisconsin Dells
Franklin Villafuerte Osorio
Word Trip Level 359
Fandango Pocatello
Shiftwizard Login Johnston
Here’s how you can get a foot detox at home!
A Small Traveling Suitcase Figgerits
Chase Bank Cerca De Mí
Amici Pizza Los Alamitos
Hell's Kitchen Valley Center Photos Menu
Property Skipper Bermuda
Aliciabibs
Pp503063
Kornerstone Funeral Tulia
Promo Code Blackout Bingo 2023
4k Movie, Streaming, Blu-Ray Disc, and Home Theater Product Reviews & News
FedEx Authorized ShipCenter - Edouard Pack And Ship at Cape Coral, FL - 2301 Del Prado Blvd Ste 690 33990
Go Nutrients Intestinal Edge Reviews
Lawrence E. Moon Funeral Home | Flint, Michigan
This Doctor Was Vilified After Contracting Ebola. Now He Sees History Repeating Itself With Coronavirus
Okta Login Nordstrom
Wera13X
Fallout 76 Fox Locations
Goosetown Communications Guilford Ct
Craigs List Sarasota
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 5753

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.