CVE-2024-11477
massInteger Underflow RCE in 7-Zip Zstandard Decompression
7-Zip contains a remote code execution flaw in its Zstandard (zstd) decompression implementation, where insufficient validation of user-supplied data allows an integer underflow before writing to memory. Exploitation requires interaction with the library — typically an application or user processing a crafted Zstandard-compressed stream or archive — and the attack vector can vary depending on how 7-Zip is integrated. A successful attacker executes arbitrary code in the context of the current process, gaining the privileges of whatever application invoked the decompressor. Anyone running an affected 7-Zip installation whose workflows decompress Zstandard data is exposed, with the highest risk on endpoints where users open untrusted archives. As of publication there is no entry in CISA's KEV and no known public proof-of-concept, but a high EPSS score (22.6% probability of exploitation within 30 days, 98th percentile) indicates an elevated near-term exploitation risk.
What to do: Upgrade 7-Zip to the latest release available from 7-zip.org and audit third-party applications that bundle or embed 7-Zip components (e.g., 7z.dll) to process archives, updating those as vendors patch. Until patched, avoid opening Zstandard-compressed archives or streams from untrusted sources, since the CVSS vector indicates user interaction is required and the attack surface varies with how the library is integrated.
| 7-Zip | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.
- Vendors
- 7-zip
- Products
- 7-zip
- Weakness
- CWE-191
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.