CVE-2018-10115: 7-Zip
High severity, CVSS 7.8. EPSS: 4.6% chance of exploitation in the next 30 days.
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Affected products
- 7-Zip 7-Zip: up to and including 18.03
Published 2018-05-02. Last modified 2026-06-17.