The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip 7 Zip | — | Upgrade 7-Zip to the latest version | Jul 30, 2024 | Jul 3, 2023 |
| Amazon_linux_2023 | — | Upgrade p7zip-plugins-debuginfoUpgrade p7zip-pluginsUpgrade p7zipUpgrade p7zip-debugsourceUpgrade p7zip-doc | Feb 17, 2025 | Jul 3, 2024 |
| Debian | — | Upgrade p7zipUpgrade 7zip | Nov 11, 2024 | Jul 3, 2024 |
| Suse | — | Upgrade p7zipUpgrade p7zip-docUpgrade p7zip-full | Jul 15, 2024 | Jul 3, 2024 |
| Ubuntu | — | Upgrade 7zip-standalone (Ubuntu Pro)Upgrade 7zip (Ubuntu Pro) | Apr 16, 2025 | Jul 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub