Loading vulnerabilities…
Loading vulnerabilities…
CVE-2024-11477
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.
This record: live connection— last retrieved: 24 September 2026 at 05:12.
Taken directly from NVD, CISA or the vendor — sometimes in English, unchanged from the source.
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack vector
LOCAL
Privileges required
NONE
User interaction
REQUIRED
Confidentiality
High
Integrity
High
Availability
High
Probability of exploitation within 30 days
22.6%
Percentile
98e
Source: FIRST.org, updated on 23 September 2026.
Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. There are no workarounds. Uninstalling the affected third-party software fully eliminates the risk of vulnerabilities. Refer to the section ‘Recommended immediate actions’.
Our own interpretation and context for the source data above.
IACS Radar assessment
Our own interpretation and context for this vulnerability — not an official source.
IACS Radar priority score
Based on CVSS 7.8, EPSS 22.6%, industrial relevance 55/100.
Combines CVSS, EPSS, KEV status, industrial relevance and exposure relevance — a complement to, not a replacement for, the individual scores below and above.
Conditions for exploitation
Operational impact & energy relevance
Possible loss of visibility of or control over the process upon successful exploitation.
Assessed as relevant to the energy sector based on: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Vendor "ABB" is a known supplier of equipment for the energy sector.
Recommended defensive measures
Industrial relevance score
Classification is provisional; manual verification by an OT security analyst is recommended.
Classified by IACS Radar-analysepijplijn (geautomatiseerd) on 24 September 2026.
IEC 62443 mapping
Automatic IACS Radar assessment based on the reported CWE weakness classification; not an official certification statement.