CVE-2025-11002
7-Zip vulnerability analysis and mitigation

Overview

CVE-2025-11002 is a directory traversal (path traversal) vulnerability in 7-Zip that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the handling of symbolic links in ZIP files, where crafted data can cause the process to traverse to unintended directories, enabling code execution in the context of a service account. It affects 7-Zip version 24.09 and was fixed in version 25.00. The vulnerability was reported to the vendor on 2025-05-02 and publicly disclosed on 2025-10-07 via the Zero Day Initiative. It carries a CVSS v3.1 base score of 7.8 (High) per NVD, and 7.0 (High) per ZDI (ZDI Advisory, NVD).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The root cause lies in 7-Zip's failure to properly validate or sanitize symbolic link targets embedded within ZIP archives during extraction. When a user opens or extracts a specially crafted ZIP file containing malicious symlinks, the extraction process follows the symlink and writes files to unintended directories outside the intended extraction path. This can be leveraged to place malicious executables or DLLs in locations that are subsequently executed, achieving remote code execution in the context of the service account running 7-Zip. User interaction (opening or extracting the malicious archive) is required, but no privileges are needed from the attacker's side (ZDI Advisory, NVD).

Impact

Successful exploitation allows an attacker to execute arbitrary code on the victim's system with the privileges of the service account or user running 7-Zip, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files, modify or delete data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The attack is particularly dangerous in environments where 7-Zip is used to automatically process untrusted archives, such as file servers, email gateways, or automated pipelines (ZDI Advisory, ThreatLocker Analysis).

Exploitability

A public proof-of-concept (PoC) exploit was released in October 2025, significantly lowering the barrier for exploitation (CyberSecurityNews PoC). The related vulnerability CVE-2025-11001 has been confirmed as actively exploited in the wild, with NHS England issuing a warning in November 2025; CVE-2025-11002 shares the same attack surface and exploitation mechanism (HelpNetSecurity, The Hacker News). The EPSS score is approximately 0.0028 (0.28%), reflecting moderate automated exploitation probability. CVE-2025-11002 does not appear in the CISA KEV catalog as of the time of this report, though active exploitation of the closely related CVE-2025-11001 has been confirmed. The vulnerability was discovered by Ryota Shiga of GMO Flatt Security Inc. (ZDI Advisory).

Exploitation steps

  1. Craft a malicious ZIP archive: Create a ZIP file containing a symbolic link that points to a sensitive or executable directory outside the intended extraction path (e.g., a symlink pointing to C:\Windows\System32\ or a startup folder on Windows).
  2. Embed a malicious payload: Include a malicious executable or DLL in the ZIP archive, named to match a file that will be placed in the traversed directory via the symlink.
  3. Deliver the archive to the victim: Distribute the crafted ZIP file via phishing email, malicious download link, or any other social engineering vector to induce the target user to open or extract it with 7-Zip.
  4. Trigger extraction: When the victim opens or extracts the ZIP file using 7-Zip 24.09 or earlier, the application follows the embedded symlink and writes the malicious payload to the unintended directory (e.g., a startup folder or a directory in the system PATH).
  5. Achieve code execution: The malicious file placed in the traversed directory is subsequently executed — either automatically (e.g., on next login via startup folder) or when a legitimate application loads the replaced DLL — resulting in arbitrary code execution in the context of the victim's service account or user session (ZDI Advisory, ThreatLocker Analysis).

Indicators of compromise

  • File System: Unexpected files written outside the intended extraction directory after a ZIP extraction; symbolic links present within extracted archive contents pointing to system directories; new or modified executables/DLLs in startup folders, %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup, or directories in the system PATH.
  • Process: 7-Zip (7z.exe, 7zG.exe, 7zFM.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, wscript.exe) shortly after archive extraction.
  • Logs: Windows Event Logs showing file creation events in sensitive directories (e.g., System32, startup folders) attributed to the 7-Zip process; audit logs recording symlink traversal or file writes outside expected extraction paths.
  • Network: Outbound connections from the 7-Zip process or newly created processes to unknown external IP addresses or C2 infrastructure following archive extraction.

Mitigation and workarounds

The vendor has released 7-Zip version 25.00, which addresses CVE-2025-11002. All users running 7-Zip 24.09 or earlier should upgrade to version 25.00 or later immediately (ZDI Advisory). As a workaround, avoid opening or extracting ZIP archives from untrusted sources, and consider using application allowlisting or sandboxing solutions to restrict 7-Zip's file system write access. Debian and its derivatives have also released updated p7zip packages addressing this vulnerability (Debian LTS Announce). Organizations using automated archive processing pipelines should audit and restrict the directories accessible to 7-Zip processes.

Community reactions

The vulnerability received significant media and community attention following the public release of a PoC exploit in October 2025, with coverage from Tom's Hardware, The Hacker News, CyberSecurityNews, and Heise (Tom's Hardware, The Hacker News). NHS England issued a public warning in November 2025 about active exploitation of the related CVE-2025-11001, which heightened awareness of both vulnerabilities (HelpNetSecurity). Security researchers and community members on Reddit, Mastodon, and Bluesky widely shared advisories urging immediate patching. SOC Prime and ThreatLocker published dedicated detection and analysis content for both CVE-2025-11001 and CVE-2025-11002 (SOC Prime, ThreatLocker Analysis).

Additional resources


SourceThis report was generated using AI

Related 7-Zip vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14266HIGH7.8
  • 7-Zip logo7-Zip
  • 7zip
NoYesJul 29, 2026
CVE-2026-48111HIGH7.1
  • 7-Zip logo7-Zip
  • cpe:2.3:a:7-zip:7-zip
NoYesJun 05, 2026
CVE-2026-48112MEDIUM6.5
  • 7-Zip logo7-Zip
  • p7zip
NoYesJun 05, 2026
CVE-2026-58052MEDIUM4.8
  • 7-Zip logo7-Zip
  • p7zip
NoYesJun 28, 2026
CVE-2026-48104MEDIUM4.2
  • 7-Zip logo7-Zip
  • p7zip
NoYesJun 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management