sentinelblue/CVE-2022-29072

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process, NOTE: multiple third parties have reported that …

PowerShellvulnerability7zipcve-2022-29072
This is stars and forks stats for /sentinelblue/CVE-2022-29072 repository. As of 20 Apr, 2024 this repository has 9 stars and 0 forks.

CVE-2022-29072 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. Uncertainty There is quite a bit of uncertainty regarding this CVE in the public. The NIST vuln details has placed a status of "awaiting analysis" for this CVE. The mitigation of this "potential" vulnerability calls for removing the 7-Zip help file ("7-zip.chm") from the installation directory of 7-Zip. If we err on the side of...
Read on GithubGithub Stats Page
repotechsstarsweeklyforksweekly
slonopotamus/stevedoreRustPowerShell257070
lando/landoShellInno SetupPowerShell3.8k05480
vimpostor/vim-lumenVim ScriptPowerShellSwift61020
ferdium/ferdium-appTypeScriptJavaScriptSCSS2k01360
microsoft/microsoft-ui-xamlC#C++PowerShell5.7k+10651+1
williamckha/spicetify-fluentCSSJavaScriptPowerShell2420160
12Knocksinna/Office365itprosPowerShell941+6469-1
Azure/azure-sdkPowerShellHTMLTypeScript431-1299+1
KelvinTegelaar/CIPP-APIPowerShellHTML12903k0
PowerShell/PowerShellGalleryPowerShell2010680