ID:11176 - Exploit for Security features bypass in 7-Zip - CVE-2025-0411

 
Main Vulnerability Database Exploits ID:11176 - Exploit for Security features bypass in 7-Zip - CVE-2025-0411

ID:11176 - Exploit for Security features bypass in 7-Zip - CVE-2025-0411

Published: February 25, 2025


Vulnerability identifier: #VU102998
Vulnerability risk: High
CVE-ID: CVE-2025-0411
CWE-ID: CWE-254
Exploitation vector: Remote access
Vulnerable software:
7-Zip

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to application ignores the Mark-of-the-Web identifier when extracting files from an archive. A remote attacker can trick the victim into executing files extracted by the application as no additional security warning occurs.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.