PT-2024-8476 · Igor Pavlov+2 · 7-Zip+2
Nicholas Zubrisky
+1
·
Published
2024-11-08
·
Updated
2025-11-22
·
CVE-2024-11477
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
The vulnerable software is 7-Zip, a widely used file compression utility. The issue arises from an integer underflow in the Zstandard decompression implementation, allowing remote attackers to execute arbitrary code on affected installations of 7-Zip by crafting specially designed archive files.
To exploit this issue, interaction with the 7-Zip library is required, but attack vectors may vary depending on the implementation. The problem stems from the lack of proper validation of user-supplied data, leading to an integer underflow before writing to memory, which an attacker can leverage to execute code in the context of the current process.
The vulnerable versions of 7-Zip are those prior to version 24.07. Users are advised to update to version 24.07 or later to mitigate this risk.
An exploit for this issue has been reported and demonstrated, highlighting the severity of the problem.
#7Zip #RemoteCodeExecution #Cybersecurity #Zstandard #IntegerUnderflow #CodeExecution #Security #UpdateNow
Exploit
Fix
RCE
Integer Underflow
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
7-Zip
Alt Linux
Red Os