SB2025012003 - Mark-of-the-Web bypass in 7-Zip



SB2025012003 - Mark-of-the-Web bypass in 7-Zip

Published: January 20, 2025 Updated: February 25, 2025

Security Bulletin ID SB2025012003
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features bypass (CVE-ID: CVE-2025-0411)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to application ignores the Mark-of-the-Web identifier when extracting files from an archive. A remote attacker can trick the victim into executing files extracted by the application as no additional security warning occurs.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.