CVE-2025-11001
AI description
CVE-2025-11001 is a vulnerability that exists within the handling of symbolic links in ZIP files by 7-Zip. Crafted data in a ZIP file can cause the application to traverse to unintended directories. This vulnerability could allow remote attackers to execute arbitrary code on affected installations of 7-Zip. To exploit this, an attacker needs to supply a malicious ZIP file containing symbolic link entries that bypass the installer's intended directory boundaries. User interaction is required to exploit this vulnerability, such as opening or extracting a malicious ZIP file. An attacker can leverage this vulnerability to execute code in the context of a service account. This issue has been fixed in 7-Zip 25.00.
- Description
- -
- Hype score
- Not currently trending
🛑 Deux nouvelles failles de sécurité découvertes dans 7-Zip - Quels sont les risques ? Comment se protéger ? 🩹 CVE-2025-11001 🩹 CVE-2025-11002 🧷 Tous les détails sur IT-Connect : https://t.co/Nu0P2E8WfX #7zip #windows #infosec https://t.co/1CiwRJBC1I
@ITConnect_fr
21 Oct 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windows users should update 7-Zip to version 25.00 or later to fix two significant “path traversal” vulnerabilities (CVE-2025-11001 and CVE-2025-11002) that can allow remote code execution, caused by the handling of symbolic links in ZIP files. https://t.co/pnCF7Kthky https:/
@AlternativeTo
20 Oct 2025
2923 Impressions
20 Retweets
62 Likes
17 Bookmarks
1 Reply
0 Quotes
7-Zipの脆弱性 CVE-2025-11001 にPoC公開-Windows向けシンボリックリンク処理の不備、v25.00で修正 https://t.co/k7l02oI80G #セキュリティ対策Lab #セキュリティ #Security #サイバー攻撃
@securityLab_jp
20 Oct 2025
105 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[1day1line] CVE-2025-11001, CVE-2025-11002: Symbolic-link handling bugs in 7-Zip leading to Arbitrary File Write / RCE potential Today’s 1day1line: 7-Zip’s ZIP extraction logic misparse Linux/WSL-style links and mistakenly treat them as Windows absolute paths, causing an htt
@hackyboiz
19 Oct 2025
1829 Impressions
5 Retweets
29 Likes
16 Bookmarks
0 Replies
0 Quotes
🚨 7-Zip PoC exploit published — two symlink-handling RCEs (CVE-2025-11001, CVE-2025-11002) in 7-Zip ≤24.09. A crafted ZIP with malicious symlinks can cause directory traversal / symlink substitution during extraction, allowing arbitrary file writes outside the target folde
@Ind_Cyber_News
19 Oct 2025
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cek out tool keren nih buat scan & test CVE-2025-11001 di 7-Zip! Dibagikan @akaclandestine : https://t.co/eyzNAAD4JK Penting banget buat yang sering pakai archiver ini. Stay secure! #CyberSecurity #InfoSec #7Zip
@BJORKANISM_REAL
19 Oct 2025
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Someone released a proof-of-concept for 7-Zip vulnerability CVE-2025-11001, arbitrary code execution via symbolic link handling. This proof-of-concept targets 7-Zip's module for converting Linux symlinks to Windows and only works on Windows. https://t.co/xhXEvzicJr
@IntCyberDigest
18 Oct 2025
5558 Impressions
17 Retweets
61 Likes
24 Bookmarks
2 Replies
0 Quotes
GitHub - shalevo13/Se7enSlip: A scanner and testter of the CVE-2025-11001 of 7-zip https://t.co/tIoVANRdCr
@akaclandestine
18 Oct 2025
3117 Impressions
9 Retweets
56 Likes
31 Bookmarks
0 Replies
0 Quotes
🚨 A public PoC exploit for 7-Zip flaws (CVE-2025-11001, CVE-2025-11002) is out — enabling file writes & possible code execution. Update to 7-Zip 25.00 now! ⚠️ Read More: https://t.co/c2thCsNh1g #CyberSecurity #7Zip #PatchNow https://t.co/3CMk8S7ctc
@FindSecCyber
18 Oct 2025
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitHub - pacbypass/CVE-2025-11001: Exploit for CVE-2025-11001 or CVE-2025-11002 https://t.co/SqAe7wZp9U
@akaclandestine
15 Oct 2025
3283 Impressions
9 Retweets
50 Likes
22 Bookmarks
0 Replies
0 Quotes
GitHub - pacbypass/CVE-2025-11001: Exploit for CVE-2025-11001 or CVE-2025-11002 - https://t.co/zzw84tPE13
@piedpiper1616
15 Oct 2025
2485 Impressions
18 Retweets
37 Likes
16 Bookmarks
0 Replies
0 Quotes
Wrote an exploit for CVE-2025-11001 in 7-zip Pretty cool bug, had fun diffing it. Blog post coming soon https://t.co/pqvHrNbJQ0
@pacbypass
15 Oct 2025
1756 Impressions
8 Retweets
20 Likes
16 Bookmarks
0 Replies
0 Quotes
Falha no 7-Zip (CVE-2025-11001 e 11002) permite execução remota no Windows. Sem autoatualização: instale 25.01/25.00 agora. Proteja-se. Vale discutir? Comente, compartilhe ou acesse. #segurança #7Zip https://t.co/RDxE1Kzp0C
@renda_Geek
14 Oct 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Se han identificado dos vulnerabilidades críticas en #7Zip (CVE-2025-11001 y CVE-2025-11002) que permiten ejecución remota de código mediante archivos ZIP manipulados. Afectan versiones anteriores a la 25.01 y requieren actualización inmediata https://t.co/jigpLnryUn https://
@henryraul
14 Oct 2025
131 Impressions
10 Retweets
10 Likes
1 Bookmark
1 Reply
1 Quote
Our Co-CTO @Ga_ryo_ and our pentesting AI agent, Takumi, have discovered arbitrary code execution vulnerabilities in 7-Zip. CVE-2025-11001: https://t.co/XowVByWd9A CVE-2025-11002: https://t.co/xBTZsI0boN Please refer to the advisories and take appropriate measures.
@flatt_sec_en
14 Oct 2025
1511 Impressions
2 Retweets
6 Likes
1 Bookmark
0 Replies
1 Quote
7-ZipにZIP解凍時のパストラバーサル 脆弱性(CVE-2025-11001,CVE-2025-11002)、今すぐアップデートを https://t.co/fB76uT0BLl #セキュリティ対策Lab #セキュリティ #Security
@securityLab_jp
13 Oct 2025
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Vulnerabilidades en 7-Zip ❗CVE-2025-11001 ❗CVE-2025-11002 ➡️Más info: https://t.co/kKWBT4jtsa https://t.co/fIJa3n25GE
@CERTpy
13 Oct 2025
114 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️世界崩壊案件 💣 人気の圧縮ソフト「7-Zip」に重大な脆弱性発覚 🧨 CVE-2025-11001/11002によりリモートから任意コード実行の恐れ 📂 シンボリックリンク処理の欠陥が原因 💥 影響範囲:最新リリース
@wow24369
13 Oct 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
壓縮工具 7-Zip 存在高風險漏洞 (CVE-2025-11001, CVE-2025-11002)。 風險:解壓縮惡意 ZIP 檔,可能導致遠端程式碼執行。 主因:7-Zip 缺乏自動更新機制,大量用戶仍在使用舊的、有漏洞的版本。 解法:請立即手動前往
@Easy2Tips
12 Oct 2025
199 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Dos vulnerabilidades críticas en 7-Zip ⚠️ CVE-2025-11001 ⚠️ CVE-2025-11002 https://t.co/ab04trVtBO https://t.co/MxO228J5V5
@elhackernet
12 Oct 2025
25978 Impressions
81 Retweets
372 Likes
95 Bookmarks
4 Replies
7 Quotes
7-Zip의 ZIP 파일 파싱 취약점(ZDI-25-949)이 공개 디렉토리 트래버설로 원격 코드 실행 가능 CVE-2025-11001 (CVSS 7.0) 25.00 버전으로 업데이트 필요https://t.co/ZUHI6MaThP
@PiesP
12 Oct 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ Abrir el archivo equivocado en 7-Zip puede comprometer tu red Dos vulnerabilidades graves (CVE-2025-11001 y CVE-2025-11002) afectan a todas las versiones de 7-Zip anteriores a la 25.00. Permiten a un atacante ejecutar código malicioso al manipular cómo se procesan en
@CycuraMX
11 Oct 2025
2252 Impressions
14 Retweets
34 Likes
16 Bookmarks
1 Reply
0 Quotes
https://t.co/SfNAVEee2o 🛑 Two high-risk vulnerabilities in 7-Zip (CVE-2025-11001, 11002) allow arbitrary code execution via crafted ZIP files. 📂 The flaws stem from symlink handling, letting archives escape extraction folders and write files anywhere on the system — eve
@GameGPU_com
11 Oct 2025
99 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Flaws (CVE-2025-11001 & CVE-2025-11002) in 7-Zip allow attackers to gain RCE by exploiting directory traversal via malicious ZIP files. Update immediately to v25.00. #7Zip #RCE #Cybersecurity #ZipFlaw #ZDI https://t.co/2ovXgisOfC
@the_yellow_fall
11 Oct 2025
262 Impressions
4 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
🚨CVE-2025-11002 and CVE-2025-11001: 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability CVSS: 7.0 / 7.0 Advisory: https://t.co/RYUZ5EoBlH and https://t.co/shEWNSXUQv Fixed in 7-Zip 25.00
@DarkWebInformer
10 Oct 2025
6158 Impressions
9 Retweets
49 Likes
16 Bookmarks
2 Replies
1 Quote
⚠️ Per chi fosse interessato: vulnerabilità ( CVE-2025-11001 e CVE-2025-11002) in #7Zip consentono agli aggressori di eseguire codice arbitrario da remoto. Aggiornamento alla versione 25.00 disponibile. 🔗 https://t.co/k2vcZGHfNp https://t.co/fLvlveEUHd
@sonoclaudio
10 Oct 2025
307 Impressions
0 Retweets
6 Likes
1 Bookmark
0 Replies
0 Quotes
7-Zipで深刻な任意コード実行の脆弱性が修正。CVE-2025-11001とCVE-2025-11002はCVSSスコア7.0。シンボリックリンクリンクの取扱いに起因。バージョン25.00で修正。GMO Flatt SecurityのRyota Shiga氏がTakumiで発見。 https://t.co/O4W
@__kokumoto
10 Oct 2025
1183 Impressions
6 Retweets
11 Likes
4 Bookmarks
0 Replies
0 Quotes
🚨 7-Zip Vulnerabilities Allow Remote Code Execution Two critical flaws (CVE-2025-11001 & CVE-2025-11002). ✅ By exploiting symbolic links in archives, attackers can execute arbitrary code - patch immediately 🎯 🔗 https://t.co/dPuEkTc7tz #CyberSecurity #News
@MME_IT
10 Oct 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability (CVE-2025-11001) #7Zip #CVE202511001 #CyberSecurity #RemoteCodeExecutionVulnerability https://t.co/S4N6sCtTr6
@SystemTek_UK
9 Oct 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes