CVE-2022-47112

CVSS 3.1 Score 2.5 of 10 (low)

Details

Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 754

Summary

CVE-2022-47112 refers to a vulnerability in 7-Zip 22.01 where the software fails to report an error for specific invalid xz files. These files contain incorrect stream flags and reserved bits, which the vulnerability allows an attacker to exploit. The exact consequences of this vulnerability are not clear, but it poses a potential risk for unintended executions or data corruption. It is important to note that some later versions of 7-Zip are reportedly not affected by this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share