PT-2024-8476 · Igor Pavlov+2 · 7-Zip+2

Nicholas Zubrisky

+1

·

Published

2024-11-08

·

Updated

2025-11-22

·

CVE-2024-11477

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The vulnerable software is 7-Zip, a widely used file compression utility. The issue arises from an integer underflow in the Zstandard decompression implementation, allowing remote attackers to execute arbitrary code on affected installations of 7-Zip by crafting specially designed archive files.
To exploit this issue, interaction with the 7-Zip library is required, but attack vectors may vary depending on the implementation. The problem stems from the lack of proper validation of user-supplied data, leading to an integer underflow before writing to memory, which an attacker can leverage to execute code in the context of the current process.
The vulnerable versions of 7-Zip are those prior to version 24.07. Users are advised to update to version 24.07 or later to mitigate this risk.
An exploit for this issue has been reported and demonstrated, highlighting the severity of the problem. #7Zip #RemoteCodeExecution #Cybersecurity #Zstandard #IntegerUnderflow #CodeExecution #Security #UpdateNow

Exploit

Fix

RCE

Integer Underflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-7364
BDU:2024-10036
CVE-2024-11477
OPENSUSE-SU-2025:15531-1
ZDI-24-1532

Affected Products

7-Zip
Alt Linux
Red Os