Record summary

CVE-2022-29072 has a selected CVSS score of 7.8 (high); EIP currently links 5 repository PoCs.

Description

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur

Description source: CVE List

Exploitation context

Available material

Repository PoCs
5

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2025 · Source: CVE List

Proofs of concept

5

Repository PoCs

GitHubkagancapar/CVE-2022-29072Repository PoCby kagancaparStars: 673Not analyzed7 files

41.1 KiB

GitHub

PoC details
GitHubtiktb8/CVE-2022-29072Repository PoCby tiktb8Stars: 6Not analyzed10 files

624.8 KiB

GitHub

PoC details
GitHubsentinelblue/CVE-2022-29072Repository PoCby sentinelblueStars: 8Not analyzed9 files

18.2 KiB

GitHub

PoC details
GitHubPhantomiman/7-Zip.chm-MitigationRepository PoCby PhantomimanStars: 3Not analyzed2 files

1.7 KiB

GitHub

PoC details
GitHubrasan2001/CVE-2022-29072Repository PoCby rasan2001Stars: 0Not analyzed1 file

416.8 KiB

GitHub

PoC details

References

6