escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur. 要約すると下記のとおり 対象製品:Windows 版 7-Zip ~21.07(最新版) 実行手順: .7z のファイルを Help > Contents エリアにドラッグ 発生リスク:権限昇格やコマンドの実行 発生原因: 7z.dll の設定ミスとヒープオーバーフロー 第18回 初心者のためのセキュリティ勉強会 kuzu7shiki HTTPS://CVE.MITRE.ORG/CGI-BIN/CVENAME.CGI?NAME=CVE-2022-29072 より引用 ` ` ` ` 5 / 13
第18回 初心者のためのセキュリティ勉強会 kuzu7shiki Tavis Ormandy @taviso Replying to @taviso @tony_bridges_el and @MalwareJake I asked them, but their explanation doesn't make much sense. I think I'm confident this CVE is going to be withdrawn. Kağan @kagancapar Replying to @taviso @jonasLyk and @MeAsHacker_HNA No, there is a heap overflow here. Let me explain here that the command execution process takes place over the CHM file after a buffer overflow. The mistake 7-zip made here is that it calls the small process that occurs after calling the API ++ 12 / 13