QID 376545

Date Published: 2022-04-19

QID 376545: 7-Zip Privilege Escalation and Command Execution Vulnerability (Zero Day)

7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers known as archives.

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area.
The zero-day included in 7-zip software is based on misconfiguration of 7z.dll and heap overflow.

Affected Versions:
7-Zip through 21.07 on Windows

QID Detection Logic (authenticated):
This QID checks for vulnerable version of 7-Zip by checking the file version of file "7z.exe" . The install location of "7z.exe" is retrieved via the registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ 7-Zip" value "InstallLocation".

Successful exploitation of the vulnerability may allow escalation of privileges and complete system compromise.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Vendor has not released any patch yet, for more information please refer to CVE-2022-29072

    Workaround:
    Users can delete the 7-zip.chm file in the 7-Zip installation directory. After deletion, attackers can no longer exploit CVE-2022-29072 vulnerability to escalate privileges.
    Vendor References

    CVEs related to QID 376545

    Software Advisories
    Advisory ID Software Component Link