CVE 7 HIGH

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability_CVE-2025-11001

7 / 10
HIGH
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.

Basic Information

ID CVE-2025-11001
Source zdi
Published Nov 19, 2025 at 21:16
Modified Nov 21, 2025 at 05:02

Affected Product

Vendor 7-Zip
Product 7-Zip
Version 24.09 (x64)
Affected Versions 7-Zip 7-Zip 24.09 (x64)

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.