The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip 7 Zip | — | Upgrade 7-Zip to the latest version | Jul 30, 2024 | Jul 3, 2023 |
| Amazon_linux_2023 | — | Upgrade p7zip-plugins-debuginfoUpgrade p7zip-pluginsUpgrade p7zip-debugsourceUpgrade p7zipUpgrade p7zip-doc | Feb 17, 2025 | Jul 3, 2024 |
| Debian | — | Upgrade 7zipUpgrade p7zip | Nov 11, 2024 | Jul 3, 2024 |
| Suse | — | Upgrade p7zipUpgrade p7zip-fullUpgrade p7zip-doc | Jul 15, 2024 | Jul 3, 2024 |
| Ubuntu | — | Upgrade 7zip (Ubuntu Pro)Upgrade 7zip-standalone (Ubuntu Pro) | Apr 16, 2025 | Jul 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub