PT-2025-32410 · Igor Pavlov+4 · 7-Zip+4

Lunbun

·

Published

2025-08-03

·

Updated

2026-06-01

·

CVE-2025-55188

CVSS v3.1

3.6

Low

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions 7-Zip versions prior to 25.01
Description An issue exists in 7-Zip where symbolic links are not always properly handled during the extraction of archives. This flaw allows a remote attacker to use a specially crafted archive to perform arbitrary file writes, which can lead to the overwriting of critical system files and potentially result in remote code execution. This issue specifically affects 7-Zip on Linux-based operating systems by bypassing security restrictions through the incorrect identification of symbolic links before file access.
Recommendations Update to version 25.01.

Exploit

Fix

DoS

RCE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11829
BDU:2025-09673
CVE-2025-55188

Affected Products

7-Zip
Alt Linux
Astra Linux
Debian
Red Os