CVE-2016-7804

Published: 05/22/2017 16:29:00
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
HIGH
CVSS v3: 7.8

Status

DocFilters Release Package State Justification Comment
25.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.4 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.4.0 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.2.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.2 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
23.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
23.2.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.2 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
22.4 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
7.8
Base Severity
HIGH
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Version
3.0

References