PT-2023-9823 · Igor Pavlov+6 · 7-Zip+6

·

CVE-2023-52169

·

Published

2023-08-18

·

Updated

2025-07-11

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions 7-Zip versions prior to 24.01
Description The issue is related to an out-of-bounds read in the NTFS handler of 7-Zip. This allows an attacker to read beyond the intended buffer, with the bytes read presented as part of a filename in the file system image. The security relevance of this issue is notable in web-service use cases where untrusted users can upload files that are then extracted by a server-side 7-Zip process. The vulnerability can be exploited by a remote attacker to upload arbitrary files and gain unauthorized access to protected information.
Recommendations For versions prior to 24.01, update to version 24.01 or later to resolve the issue. As a temporary workaround, consider restricting the use of the NTFS handler in 7-Zip to minimize the risk of exploitation. Avoid using 7-Zip to extract files from untrusted sources until the issue is resolved.

Fix

Out of bounds Read

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15154
ALT-PU-2024-15240
BDU:2024-04975
BDU:2024-11604
CVE-2023-52169
OESA-2025-1748
OPENSUSE-SU-2024_2625-1
SUSE-SU-2024:2475-1
SUSE-SU-2024:2625-1
USN-7438-1

Affected Products

7-Zip
Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu