Remote Code Execution Vulnerabilities in 7-Zip via Malicious ZIP Archives
Two high-severity vulnerabilities in the widely used open-source compression utility 7-Zip have been disclosed, allowing attackers to achieve remote code execution by leveraging specially crafted ZIP archives. The flaws, identified as CVE-2025-11001 and CVE-2025-11002, were reported by Trend Micro’s Zero Day Initiative and affect multiple builds of 7-Zip. These vulnerabilities arise from improper parsing of symbolic links within ZIP files, enabling a malicious archive to escape its intended extraction directory and write files to arbitrary locations on the victim’s system. If exploited, this directory traversal can be chained to execute arbitrary code with the privileges of the user running 7-Zip, potentially compromising the entire Windows environment. Both vulnerabilities have been assigned a CVSS base score of 7.0, reflecting their significant risk. Exploitation requires minimal user interaction; simply opening or extracting a malicious ZIP file is sufficient to trigger the attack. The vulnerabilities were quietly patched in 7-Zip version 25.00, released on July 5, 2025, but details were not publicly disclosed until October, leaving users unaware and exposed for several months if they had not updated. The lack of an automatic update mechanism in 7-Zip exacerbates the risk, as many users may not be running the latest, patched version. The vulnerabilities specifically allow attackers to overwrite or plant payloads in sensitive system paths, which can be used to hijack execution flow and escalate privileges. Security advisories emphasize the importance of updating to version 25.00 or later to mitigate these risks. The flaws highlight the ongoing challenges in securing widely deployed open-source tools, especially those lacking robust update mechanisms. Organizations relying on 7-Zip for file compression and extraction should prioritize patching and consider additional controls to limit the impact of potential exploitation. The vulnerabilities underscore the need for user awareness regarding the risks of opening files from untrusted sources. Security researchers warn that similar directory traversal and symlink handling issues may exist in other archiving tools, warranting broader scrutiny. The incident demonstrates the value of coordinated vulnerability disclosure and timely patch adoption. Enterprises are advised to audit their environments for outdated 7-Zip installations and deploy the latest version as a matter of urgency. The disclosure also serves as a reminder for software maintainers to implement secure default behaviors and consider automated update features to protect end users.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Users are urged to update 7-Zip to version 25
Reporting on the vulnerabilities stated that affected users should upgrade to 7-Zip version 25 as the recommended remediation. This marked the public availability of a fixed or safer version in response to the disclosed flaws.
7-Zip vulnerabilities CVE-2025-11001 and CVE-2025-11002 are disclosed
Two high-severity flaws in 7-Zip, tracked as CVE-2025-11001 and CVE-2025-11002, were publicly reported as allowing code execution through malicious ZIP archives. The disclosures described the issues as exposing users to remote attack via crafted archive files.
Sources
2 references tracked. Mallory keeps watching after this page renders.
New 7-Zip high-severity vulnerabilities expose systems to remote attackers — users should update to version 25 ASAP
tomshardware.com
Open sourceTwo 7-Zip Flaws Allow Code Execution via Malicious ZIP Files (CVE-2025-11001 & CVE-2025-11002)
securityonline.info
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


