7-Zip
cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*, +2 more
A directory traversal vulnerability allowing remote code execution has been identified in 7-Zip. This issue arises from the application's handling of symbolic links within ZIP files. Crafted ZIP file data can manipulate the extraction process to access unintended directories. As a result, an attacker could execute arbitrary code, potentially under the context of a service account. Exploitation of this vulnerability requires user interaction and may vary based on the specific implementation.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Users can upgrade to 7-Zip version 25.00 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.