CVE-2022-29072
HIGH 7.8EPSS 1.5%
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 1.54% chance of exploitation in the next 30 days, 73th percentile
- Published
- 2022-04-15
- Updated
- 2025-06-09
Proof-of-concept exploits (5)
- kagancapar/CVE-2022-29072673★ · 2022-04-22
- https://www.youtube.com/watch?v=sT1cvbu7ZTA
- rasan2001/CVE-2022-290720★ · 2024-05-10
- sentinelblue/CVE-2022-290728★ · 2022-04-20
- tiktb8/CVE-2022-290726★ · 2022-04-18