CVE-2018-10115
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 4.6%
from disclosure to weapon
Published on NVDMay 2
VulnCheck+664d
exploitation probability
4.6%top 9% of all CVEs
observed exploitation
yesVulnCheck
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Affected products
n/a · n/a