Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilityproof-of-concept-releasewidely-deployed-product-advisory

Active Exploitation of 7-Zip Symbolic Link Vulnerability (CVE-2025-11001)

Updated 23h agoFirst seen Nov 19, 20256 sources

Attackers are actively exploiting a critical vulnerability in 7-Zip, identified as CVE-2025-11001, which allows remote code execution through improper handling of symbolic links in ZIP files. The flaw, introduced in 7-Zip version 21.02 and fixed in version 25.00, enables attackers to craft malicious ZIP archives that can traverse directories and execute code in the context of a service account, but only on Windows systems with elevated privileges or Developer Mode enabled. NHS England Digital and multiple security researchers have confirmed active exploitation in the wild, and proof-of-concept exploits have been published, increasing the urgency for organizations to update affected systems.

The vulnerability was discovered by Ryota Shiga of GMO Flatt Security using an AI-powered application security auditor and was publicly disclosed via the Zero Day Initiative. Security advisories emphasize that exploitation is limited to specific Windows configurations, but the presence of public PoC code raises the risk of broader attacks. Users and organizations are strongly advised to upgrade to 7-Zip version 25.00 or later to mitigate the threat and prevent potential compromise from malicious ZIP files leveraging this vulnerability.

Share:
Active Exploitation of 7-Zip Symbolic Link Vulnerability (CVE-2025-11001)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Nov 23, 20257mo ago

Microsoft begins tracking related malicious activity

Microsoft reported that it was tracking malicious activity related to exploitation attempts for CVE-2025-11001 under a specific detection name. This indicated vendor awareness and monitoring of abuse tied to the 7-Zip flaw.

Nov 19, 20257mo ago

NHS England Digital warns CVE-2025-11001 is being actively exploited

NHS England Digital issued an alert that CVE-2025-11001, a 7-Zip remote code execution flaw, was being actively exploited in the wild. The agency did not identify the threat actor or provide details on how the vulnerability was being weaponized.

Public proof-of-concept exploit for CVE-2025-11001 emerges

A researcher using the name "pacbypass" released a working proof-of-concept exploit for CVE-2025-11001, increasing the risk of abuse. The PoC author said exploitation is limited to Windows and generally requires an elevated user or service account context, or a machine with Developer Mode enabled.

Technical details of CVE-2025-11001 are publicly disclosed

Trend Micro's Zero Day Initiative publicly described CVE-2025-11001 as an improper handling of symbolic links in ZIP archives that can write outside the intended extraction path. The disclosure explained that exploitation could lead to code execution in the context of a service or elevated account on Windows systems.

Jul 1, 20251y ago

7-Zip 25.00 released with fixes for CVE-2025-11001 and CVE-2025-11002

7-Zip version 25.00 was released in July 2025 to patch CVE-2025-11001, a symbolic link handling flaw that can enable directory traversal and remote code execution, as well as the related CVE-2025-11002. The update required manual or enterprise-managed deployment because 7-Zip lacks an internal auto-update mechanism.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Affected products
3 linked
7-Zip7-ZipWindows
Organizations
7 linked
7-ZipTrend MicroGMO Flatt SecurityMicrosoft CorporationHackread.comMondooNHS England Digital
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.