Update regarding CVE-2022-29072 (7-Zip Vulnerability)

CVE Source: CVE - CVE-2022-29072

Syncro has become aware of the recent vulnerability related to the 7-Zip application, allowing for privilege escalation on a local system via malicious file drop. Syncro is not vulnerable as a result of this issue.

For users who do have 7-Zip installed, a patch has not yet been released and recommendations are to remove the vulnerable chm file from your system(s). We have published a script to remove the vulnerable file in our Community Scripts repository, provided by our users.

The following steps can be used to remove the vulnerable file 7-zip.chm:

  1. Import the removal script into your script library. Link to script
  2. Create a Saved Asset Search to quickly make a list of all assets that have 7-Zip installed by going to your ‘Asset & RMM’ tab and selecting the magnifying glass.

    Next, select the ‘New Search’ button and enter ‘7-Zip’ in the ‘Installed Application’ field.
    After saving the search, it will be visible in your Saved Asset Search list.
  3. We can use this search now to run the 'Remove 7-Zip.chm from default install paths’ script in bulk. Select the search that was just made, select all the assets, and select ‘Run Script’ from the ‘Manage’ dropdown.
  4. The last step is to select the script from the ‘Script’ dropdown and press the ‘Run’ button:

    Do NOT select the ‘Skip Offline Assets’ checkbox. With that unselected, the script will stay in a pending state on offline assets until the asset comes back online and run shortly after the asset is back online. This will ensure that all assets run the script regardless of their online status.

Note: The assets will still be shown on the asset search after the script successfully runs since the script is only removing the vulnerable file and not the entire application.

1 Like

This CVE is disputed, and possibly a vulnerability in all .chm files related to the hh.exe (HTML Helper EXE).

No reason you couldn’t delete all of the 7-zip’s chm files, but this same thin likely also applies to numerous other programs

1 Like

A step is missing, Change the default timeout for php execution to 0. Otherwise it times out in 10 min
Powershell TimeOut Setting

Where can I get a report on all assets - Success or Failure ? I only see the first five results in the edit scripts tab. Full file only shows current script status.