PT-2025-41204 · Igor Pavlov +1 · 7-Zip +1

Published

2025-01-01

·

Updated

2025-11-28

·

CVE-2025-11002

CVSS v2.0
6.2
VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 7-Zip (affected versions not specified)
Description The issue concerns a flaw in the 7-Zip file archiver related to incorrect handling of symbolic links before file access. Exploitation may allow an attacker to execute arbitrary code if a user opens a specially crafted ZIP archive. The vulnerability involves a directory traversal that could lead to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-12912
CVE-2025-11002
ZDI-25-950

Affected Products

7-Zip
Debian