CVE-2022-29072

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
15/04/2022
Last modified:
09/06/2025

Description

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* 21.07 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*