PT-2025-32410 · Igor Pavlov+4 · 7-Zip+4
Lunbun
·
Published
2025-08-03
·
Updated
2026-06-01
·
CVE-2025-55188
CVSS v3.1
3.6
Low
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
7-Zip versions prior to 25.01
Description
An issue exists in 7-Zip where symbolic links are not always properly handled during the extraction of archives. This flaw allows a remote attacker to use a specially crafted archive to perform arbitrary file writes, which can lead to the overwriting of critical system files and potentially result in remote code execution. This issue specifically affects 7-Zip on Linux-based operating systems by bypassing security restrictions through the incorrect identification of symbolic links before file access.
Recommendations
Update to version 25.01.
Exploit
Fix
DoS
RCE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
7-Zip
Alt Linux
Astra Linux
Debian
Red Os