Vulnerability record · CVE-2023-31102 · published 3 November 2023
CVE-2023-31102: 7-Zip Ppmd7 integer underflow allows invalid read via crafted 7Z archive
7 Zip · 7 Zip
7-Zip before 23.00 contains an integer underflow in Ppmd7.c that leads to an invalid read when processing a crafted 7Z archive. The flaw is reachable when a user opens or extracts a malicious archive, and it can corrupt memory in a way that affects confidentiality, integrity and availability.
Description
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with local vector and user interaction, combined with a very high EPSS percentile, makes this a high-priority fix for environments where users open untrusted archives.
What it is
7-Zip before 23.00 contains an integer underflow in Ppmd7.c that leads to an invalid read when processing a crafted 7Z archive. The flaw is reachable when a user opens or extracts a malicious archive, and it can corrupt memory in a way that affects confidentiality, integrity and availability.
Impact
An attacker who gets a victim to open a crafted 7Z archive can trigger an out-of-bounds read and memory corruption, potentially leading to code execution in the context of the 7-Zip process or a crash.
Attack surface
The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the attacker must deliver a malicious 7Z file and convince the user to open or extract it. No authentication is needed on the target system.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.57 (99th percentile), indicating elevated likelihood of exploitation activity; reference tags are advisory and issue-tracking only, with no public exploit tag supplied.
What to do
- Upgrade 7-Zip to version 23.00 or later on all endpoints and build systems.
- Apply the NetApp advisory updates for Active IQ Unified Manager and OnCommand Workflow Automation where 7-Zip components are bundled.
- Block or quarantine untrusted 7Z archives at email and web gateways until patching is complete.
- Restrict execution of 7-Zip binaries to approved users and paths where feasible.
- Inventory third-party software that embeds 7-Zip and track it for the same fix.
Detection
- Monitor for 7-Zip process crashes or abnormal termination events tied to archive extraction.
- Alert on 7z.exe or 7za.exe spawning child processes or making unexpected network connections after opening an archive.
- Scan file shares and mail attachments for 7Z archives from untrusted sources and inspect them in a sandbox.
- Use EDR to flag memory-read anomalies or access violations in 7-Zip modules during extraction.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://ds-security.com/post/integer-overflow-in-7-zip-cve-2023-31102/ | |
| https://security.netapp.com/advisory/ntap-20231110-0007/ | Third Party Advisory |
| https://sourceforge.net/p/sevenzip/discussion/45797/thread/713c8a8269/ | Issue TrackingRelease Notes |
| https://www.7-zip.org/download.html | Product |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1165/ | Third Party AdvisoryVDB Entry |
| https://ds-security.com/post/integer-overflow-in-7-zip-cve-2023-31102/ | |
| https://security.netapp.com/advisory/ntap-20231110-0007/ | Third Party Advisory |
| https://sourceforge.net/p/sevenzip/discussion/45797/thread/713c8a8269/ | Issue TrackingRelease Notes |
| https://www.7-zip.org/download.html | Product |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1165/ | Third Party AdvisoryVDB Entry |
Track CVE-2023-31102 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-31102), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.