Security features bypass in 7-Zip - CVE-2025-0411
Published: January 20, 2025 / Updated: March 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to application ignores the Mark-of-the-Web identifier when extracting files from an archive. A remote attacker can trick the victim into executing files extracted by the application as no additional security warning occurs.
Note, the vulnerability is being actively exploited in the wild.
Affected software
MELSOFT Update Manager SW1DND-UDM-M
Quick Assist for Windows
How to mitigate CVE-2025-0411
MELSOFT Update Manager SW1DND-UDM-M - update to 1.013P
Quick Assist for Windows - addressed in versions 2.4.176, 3.3.0