PT-2025-41203 · Igor Pavlov+2 · 7-Zip+2

Published

2025-01-01

·

Updated

2026-05-12

·

CVE-2025-11001

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 7-Zip versions prior to 25.00
Description A flaw exists in the ZIP file parsing logic regarding the handling of symbolic links. An attacker can craft a malicious ZIP file containing symbolic links that cause the application to traverse to unintended directories during extraction. This directory traversal allows files to be written to arbitrary system locations, which can be leveraged to execute arbitrary code in the context of the service account running 7-Zip. Exploitation requires user interaction, specifically the opening of a specially crafted archive. This issue has been reported as being used in phishing campaigns.
Recommendations Update to version 25.00 or newer. Enforce sandboxing where possible. Run 7-Zip under reduced privileges.

Exploit

Fix

DoS

RCE

Path traversal

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-12910
BDU:2025-12912
CVE-2025-11001
ZDI-25-949

Affected Products

7-Zip
Debian
Red Os