The vendor explicitly identifies these products as affected by this CVE.
- ABB 800xA History <=7.0
- ABB 800xA for AC 870P Melody <=6.2
- ABB 800xA for Symphony Plus Harmony <=6.2
- ABB Batch Management <=6.2
- ABB Application Change Management <=6.2
- ABB Production Response Batch History <=6.2
- Summary
- 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process.
- Remediation
- Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. There are no workarounds. Uninstalling the affected third-party software fully eliminates the risk of vulnerabilities. Refer to the section ‘Recommended immediate actions’.
