The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip 7 Zip | — | Upgrade 7-Zip to the latest version | Jul 30, 2024 | Jul 3, 2023 |
| Amazon_linux_2023 | — | Upgrade p7zip-docUpgrade p7zip-plugins-debuginfoUpgrade p7zipUpgrade p7zip-debugsourceUpgrade p7zip-plugins | Feb 17, 2025 | Jul 3, 2024 |
| Debian | — | Upgrade p7zipUpgrade 7zip | Nov 11, 2024 | Jul 3, 2024 |
| Suse | — | Upgrade p7zip-docUpgrade p7zipUpgrade p7zip-full | Jul 15, 2024 | Jul 3, 2024 |
| Ubuntu | — | Upgrade 7zip-standalone (Ubuntu Pro)Upgrade 7zip (Ubuntu Pro) | Apr 16, 2025 | Jul 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub