Logo
vulnerabilityCVE-2018-10172
Name
CVE-2018-10172
Source
NVD ( link)Debian ( link)
Description
7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it easier for attackers to bypass intended access restrictions by using this privilege in the context of a sandboxed process. Note: This has been disputed by 3rd parties who argue this is a valid feature of Windows.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
p7zip
Exploitable

Vulnerability Ratings#


8.8
other
7.2
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.06
Exploitable
buildroot
master
17.06
Exploitable
yocto
scarthgap
16.02
Exploitable