PT-2025-41204 · Igor Pavlov +1 · 7-Zip +1

Published

2025-01-01

·

Updated

2025-12-18

·

CVE-2025-11002

CVSS v2.0
6.2
VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 7-Zip (affected versions not specified)
Description The issue concerns an incorrect handling of symbolic links before file access within the 7-Zip file archiver. Successful exploitation may allow an attacker to execute arbitrary code when a specially crafted ZIP archive is opened by a user. The issue involves a directory traversal, potentially leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-12912
CVE-2025-11002
ZDI-25-950

Affected Products

7-Zip
Debian