Summary
Details released regarding a security vulnerability – already patched by the vendor in June 2024 – present in the well-known open source file compression and archiving software 7-Zip. This vulnerability could be exploited by a remote attacker to execute arbitrary code on the affected systems.
Risk
Estimate of the impact of the vulnerability on the reference community: MEDIUM/YELLOW (63.84/100)1.
Type
- Remote Code Execution
Affected products and versions
7-Zip, versions prior to 24.07
Mitigation actions
If not done, it is recommended to update the vulnerable products following the instructions in the security bulletin reported in the References section.
Unique Vulnerability Identifiers
References
https://www.zerodayinitiative.com/advisories/ZDI-24-1532
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.