Privilege Escalation Vulnerability in 7-Zip on Windows
CVE-2018-10172
8.8HIGH
What is CVE-2018-10172?
7-Zip versions through 18.01 on Windows implement the 'Large memory pages' option by calling the LsaAddAccountRights function. This implementation adds the SeLockMemoryPrivilege privilege to user accounts, potentially enabling attackers to circumvent established access controls. While this feature has been a topic of debate among security experts regarding its validity within Windows, the implications for system security cannot be overlooked, especially in a sandboxed environment.