Cyber Security News

7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code Remotely

Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip, which could allow remote attackers to execute arbitrary code.

Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.

The core of both vulnerabilities lies within the way 7-Zip handles symbolic links embedded in ZIP archives. According to the advisory, a threat actor can create a malicious ZIP file containing crafted data that exploits this weakness.

When a user with a vulnerable version of 7-Zip attempts to decompress the archive, the flawed process can be manipulated to perform a directory traversal.

This allows the extraction process to write files outside of the intended destination folder, potentially placing malicious payloads in sensitive system locations.

While the attack is initiated remotely through the delivery of the malicious file, exploitation requires user interaction, as the victim must choose to open the archive. The specific attack vectors may vary depending on how 7-Zip is implemented within different environments.

Both CVE-2025-11001 and CVE-2025-11002 have been assigned a CVSS 3.0 score of 7.0, classifying them as high-severity threats.

A successful exploit could allow an attacker to execute arbitrary code on the affected system with the privileges of the service account or user running the 7-Zip application.

This could lead to a full system compromise, data theft, or the deployment of further malware such as ransomware.

The high complexity of the attack and the requirement for user interaction prevent the vulnerabilities from receiving a critical rating, but the potential impact on confidentiality, integrity, and availability remains significant given the widespread use of the 7-Zip utility.

CVE IDAffected ProductVulnerabilityCVSS 3.0 Score
CVE-2025-110027-Zip (versions before 25.00)Arbitrary Code Execution via Symbolic Link Handling7.0 (High)
CVE-2025-110017-Zip (versions before 25.00)Arbitrary Code Execution via Symbolic Link Handling7.0 (High)

The developer of 7-Zip has released version 25.00, which rectifies these security flaws. All users are strongly advised to update their installations immediately to protect against potential exploitation.

The vulnerabilities were initially reported to the vendor on May 2, 2025, following a responsible disclosure timeline.

A coordinated public advisory was subsequently released on October 7, 2025, to inform the public of the risks and the available patch. These vulnerabilities were uncovered by security researcher Ryota Shiga of GMO Flatt Security Inc., working with takumi-san.ai.

Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial…

2 hours ago

Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances…

3 hours ago

Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture

Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native…

3 hours ago

175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Socket's Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages…

4 hours ago

RondoDox Botnet Exploits 50+ Vulnerabilities to Attack Routers, CCTV Systems and Web Servers

Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive…

4 hours ago

Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life

Microsoft Defender for Endpoint is incorrectly flagging specific versions of SQL Server as having reached…

6 hours ago