7-Zip NTFS Handler Vulnerable to Out-of-Bounds Read Attack
CVE-2023-52169
8.2HIGH
What is CVE-2023-52169?
The 7-Zip software, specifically its NTFS handler, is susceptible to an out-of-bounds read vulnerability that enables attackers to read data beyond the intended memory buffer. This issue arises from how the application processes filenames in file system images and poses a threat in environments where untrusted users can upload files for extraction using a server-side 7-Zip process. If exploited, this vulnerability may lead to unauthorized access to sensitive data hidden within filenames.
