CVE-2016-2334
Title: 7-Zip RCE
Memory Corruption
Proof Of Concept
PoC Available for CVE-2016-2334
CWE Category
CWE-119
Published Date
Dec 13, 2016
Modified Date
May 06, 2026
Exploit Status
Available
Score
7.8
CVSS v3.0
Exploit Probability (EPSS)
14.79%
Vulnerability Summary
CVE-2016-2334: Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
Impacted Vendors
Reference Links
http://blog.talosintel.com/2016/05/multiple-7-zip-vulnerabilities.html
http://blog.talosintelligence.com/2017/11/exploiting-cve-2016-2334.html
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
http://www.securityfocus.com/bid/90531
http://www.securitytracker.com/id/1035876
http://www.talosintel.com/reports/TALOS-2016-0093/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNYIQAU3FKFBNFPK6GKYTSVRHQA7PTYT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DTGWICT3KYYDPDXRNO5SXD32GZICGRIR/
https://security.gentoo.org/glsa/201701-27
http://blog.talosintel.com/2016/05/multiple-7-zip-vulnerabilities.html
http://blog.talosintelligence.com/2017/11/exploiting-cve-2016-2334.html
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
http://www.securityfocus.com/bid/90531
http://www.securitytracker.com/id/1035876
http://www.talosintel.com/reports/TALOS-2016-0093/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNYIQAU3FKFBNFPK6GKYTSVRHQA7PTYT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DTGWICT3KYYDPDXRNO5SXD32GZICGRIR/
https://security.gentoo.org/glsa/201701-27
CVSS v3.0
Source Entity
[email protected]
Severity
HIGH
7.8
Attack Vector
LOCAL
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
9.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2016-2334 Exploits & PoCs (Proof Of Concept)
GitHub
https://github.com/icewall/CVE-2016-2334
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
LOCAL
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
CVSS Vector String
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Stack
No specific products linked.