Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2024-11477

HIGH 7.8

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 21.99% moderate exploit risk percentile 97.4%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • 7-Zip Windows winget:7zip.7zip
    Affected <24.07 Fixed in 24.07 Latest tracked 26.02 patched
Vulnerable CPE configurations (1)
Vendor Product Versions
7-zip 7-zip
All platforms (wildcard)
<24.07
View on NVD ↗