7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 09 Jun 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 |
Mon, 09 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-09T14:47:09.625Z
Reserved: 2022-04-12T00:00:00.000Z
Link: CVE-2022-29072
Updated: 2024-08-03T06:10:59.387Z
Status : Modified
Published: 2022-04-15T20:15:12.313
Modified: 2025-06-09T15:15:27.197
Link: CVE-2022-29072
No data.
OpenCVE Enrichment
No data.
Weaknesses