CVE Feed

    Dashboard / CVE / CVE-2022-29072

    CVE-2022-29072

    7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur

    Published:Apr 15, 2022
    Last Modified:Jun 9, 2025
    EPS:Apr 15, 2022
    EPSS Score:0.15543
    CVSS Score:7.8

    Affected Products

    Vendor
    7-zip
    Product
    7-zip
    Vendor
    Microsoft
    Product
    Windows

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High