Out-of-bounds write in 7-Zip - CVE-2023-40481
Published: August 25, 2023
Vulnerability identifier: #VU80002
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40481
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when parsing SQFS files. A remote attacker can create a specially crafted archive, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
7-Zip
Dell EMC VxRail Appliance
APEX Cloud Platform for Microsoft Azure
AADvance Trusted SIS Workstation
Dell EMC VxRail Appliance
APEX Cloud Platform for Microsoft Azure
AADvance Trusted SIS Workstation
How to mitigate CVE-2023-40481
Install updates from vendor's website.
7-Zip - update to 23.00
Dell EMC VxRail Appliance - update to 7.0.540
APEX Cloud Platform for Microsoft Azure - update to 01.03.00.00
AADvance Trusted SIS Workstation - update to 2.00.02
Dell EMC VxRail Appliance - update to 7.0.540
APEX Cloud Platform for Microsoft Azure - update to 01.03.00.00
AADvance Trusted SIS Workstation - update to 2.00.02