7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur
- http://packetstormsecurity.com/files/166763/7-Zip-21.07-Code-Execution-Privilege-Escalation.html
- https://github.com/kagancapar/CVE-2022-29072
- https://news.ycombinator.com/item?id=31070256
- https://www.youtube.com/watch?v=sT1cvbu7ZTA
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CVEDB/PoC-List
- https://github.com/CVEDB/awesome-cve-repo
- https://github.com/CVEDB/top
- https://github.com/GhostTroops/TOP
- https://github.com/JERRY123S/all-poc
- https://github.com/Mr-xn/Penetration_Testing_POC
- https://github.com/NaInSec/CVE-PoC-in-GitHub
- https://github.com/Phantomiman/7-Zip.chm-Mitigation
- https://github.com/SYRTI/POC_to_review
- https://github.com/SnailDev/github-hot-hub
- https://github.com/WhooAmii/POC_to_review
- https://github.com/adeshrr/nessus-vulnerability-scanner
- https://github.com/changtraixuqang97/changtraixuqang97
- https://github.com/cyberanand1337x/bug-bounty-2022
- https://github.com/duytruongpham/duytruongpham
- https://github.com/goldenscale/GS_GithubMirror
- https://github.com/hktalent/TOP
- https://github.com/izj007/wechat
- https://github.com/jbmihoub/all-poc
- https://github.com/k0mi-tg/CVE-POC
- https://github.com/kagancapar/7-zip-malicious-code-vulnerability
- https://github.com/kagancapar/CVE-2022-29072
- https://github.com/karimhabush/cyberowl
- https://github.com/kun-g/Scraping-Github-trending
- https://github.com/lions2012/Penetration_Testing_POC
- https://github.com/lonnyzhang423/github-hot-hub
- https://github.com/manas3c/CVE-POC
- https://github.com/mt190502/stars
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/notmariekondo/notmariekondo
- https://github.com/pipiscrew/timeline
- https://github.com/priamai/sigmatau
- https://github.com/rasan2001/CVE-2022-29072
- https://github.com/sentinelblue/CVE-2022-29072
- https://github.com/taielab/awesome-hacking-lists
- https://github.com/tiktb8/CVE-2022-29072
- https://github.com/trhacknon/Pocingit
- https://github.com/weeka10/-hktalent-TOP
- https://github.com/whoforget/CVE-POC
- https://github.com/xuetusummer/Penetration_Testing_POC
- https://github.com/youwizard/CVE-POC
- https://github.com/zecool/cve
- https://github.com/zoroqi/my-awesome