CVE-2025-11001

7-Zip

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-11001 is a vulnerability that exists within the handling of symbolic links in ZIP files by 7-Zip. Crafted data in a ZIP file can cause the application to traverse to unintended directories. This vulnerability could allow remote attackers to execute arbitrary code on affected installations of 7-Zip. To exploit this, an attacker needs to supply a malicious ZIP file containing symbolic link entries that bypass the installer's intended directory boundaries. User interaction is required to exploit this vulnerability, such as opening or extracting a malicious ZIP file. An attacker can leverage this vulnerability to execute code in the context of a service account. This issue has been fixed in 7-Zip 25.00.

Description
-

Social media

Hype score
Not currently trending
  1. 🛑 Deux nouvelles failles de sécurité découvertes dans 7-Zip - Quels sont les risques ? Comment se protéger ? 🩹 CVE-2025-11001 🩹 CVE-2025-11002 🧷 Tous les détails sur IT-Connect : https://t.co/Nu0P2E8WfX #7zip #windows #infosec https://t.co/1CiwRJBC1I

    @ITConnect_fr

    21 Oct 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Windows users should update 7-Zip to version 25.00 or later to fix two significant “path traversal” vulnerabilities (CVE-2025-11001 and CVE-2025-11002) that can allow remote code execution, caused by the handling of symbolic links in ZIP files. https://t.co/pnCF7Kthky https:/

    @AlternativeTo

    20 Oct 2025

    2923 Impressions

    20 Retweets

    62 Likes

    17 Bookmarks

    1 Reply

    0 Quotes

  3. 7-Zipの脆弱性 CVE-2025-11001 にPoC公開-Windows向けシンボリックリンク処理の不備、v25.00で修正 https://t.co/k7l02oI80G #セキュリティ対策Lab #セキュリティ #Security #サイバー攻撃

    @securityLab_jp

    20 Oct 2025

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. [1day1line] CVE-2025-11001, CVE-2025-11002: Symbolic-link handling bugs in 7-Zip leading to Arbitrary File Write / RCE potential Today’s 1day1line: 7-Zip’s ZIP extraction logic misparse Linux/WSL-style links and mistakenly treat them as Windows absolute paths, causing an htt

    @hackyboiz

    19 Oct 2025

    1829 Impressions

    5 Retweets

    29 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 7-Zip PoC exploit published — two symlink-handling RCEs (CVE-2025-11001, CVE-2025-11002) in 7-Zip ≤24.09. A crafted ZIP with malicious symlinks can cause directory traversal / symlink substitution during extraction, allowing arbitrary file writes outside the target folde

    @Ind_Cyber_News

    19 Oct 2025

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Cek out tool keren nih buat scan & test CVE-2025-11001 di 7-Zip! Dibagikan @akaclandestine : https://t.co/eyzNAAD4JK Penting banget buat yang sering pakai archiver ini. Stay secure! #CyberSecurity #InfoSec #7Zip

    @BJORKANISM_REAL

    19 Oct 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 Someone released a proof-of-concept for 7-Zip vulnerability CVE-2025-11001, arbitrary code execution via symbolic link handling. This proof-of-concept targets 7-Zip's module for converting Linux symlinks to Windows and only works on Windows. https://t.co/xhXEvzicJr

    @IntCyberDigest

    18 Oct 2025

    5558 Impressions

    17 Retweets

    61 Likes

    24 Bookmarks

    2 Replies

    0 Quotes

  8. GitHub - shalevo13/Se7enSlip: A scanner and testter of the CVE-2025-11001 of 7-zip https://t.co/tIoVANRdCr

    @akaclandestine

    18 Oct 2025

    3117 Impressions

    9 Retweets

    56 Likes

    31 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 A public PoC exploit for 7-Zip flaws (CVE-2025-11001, CVE-2025-11002) is out — enabling file writes & possible code execution. Update to 7-Zip 25.00 now! ⚠️ Read More: https://t.co/c2thCsNh1g #CyberSecurity #7Zip #PatchNow https://t.co/3CMk8S7ctc

    @FindSecCyber

    18 Oct 2025

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. GitHub - pacbypass/CVE-2025-11001: Exploit for CVE-2025-11001 or CVE-2025-11002 https://t.co/SqAe7wZp9U

    @akaclandestine

    15 Oct 2025

    3283 Impressions

    9 Retweets

    50 Likes

    22 Bookmarks

    0 Replies

    0 Quotes

  11. GitHub - pacbypass/CVE-2025-11001: Exploit for CVE-2025-11001 or CVE-2025-11002 - https://t.co/zzw84tPE13

    @piedpiper1616

    15 Oct 2025

    2485 Impressions

    18 Retweets

    37 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  12. Wrote an exploit for CVE-2025-11001 in 7-zip Pretty cool bug, had fun diffing it. Blog post coming soon https://t.co/pqvHrNbJQ0

    @pacbypass

    15 Oct 2025

    1756 Impressions

    8 Retweets

    20 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  13. Falha no 7-Zip (CVE-2025-11001 e 11002) permite execução remota no Windows. Sem autoatualização: instale 25.01/25.00 agora. Proteja-se. Vale discutir? Comente, compartilhe ou acesse. #segurança #7Zip https://t.co/RDxE1Kzp0C

    @renda_Geek

    14 Oct 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Se han identificado dos vulnerabilidades críticas en #7Zip (CVE-2025-11001 y CVE-2025-11002) que permiten ejecución remota de código mediante archivos ZIP manipulados. Afectan versiones anteriores a la 25.01 y requieren actualización inmediata https://t.co/jigpLnryUn https://

    @henryraul

    14 Oct 2025

    131 Impressions

    10 Retweets

    10 Likes

    1 Bookmark

    1 Reply

    1 Quote

  15. Our Co-CTO @Ga_ryo_ and our pentesting AI agent, Takumi, have discovered arbitrary code execution vulnerabilities in 7-Zip. CVE-2025-11001: https://t.co/XowVByWd9A CVE-2025-11002: https://t.co/xBTZsI0boN Please refer to the advisories and take appropriate measures.

    @flatt_sec_en

    14 Oct 2025

    1511 Impressions

    2 Retweets

    6 Likes

    1 Bookmark

    0 Replies

    1 Quote

  16. 7-ZipにZIP解凍時のパストラバーサル 脆弱性(CVE-2025-11001,CVE-2025-11002)、今すぐアップデートを https://t.co/fB76uT0BLl #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    13 Oct 2025

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ⚠️Vulnerabilidades en 7-Zip ❗CVE-2025-11001 ❗CVE-2025-11002 ➡️Más info: https://t.co/kKWBT4jtsa https://t.co/fIJa3n25GE

    @CERTpy

    13 Oct 2025

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. ⚠️世界崩壊案件 💣 人気の圧縮ソフト「7-Zip」に重大な脆弱性発覚 🧨 CVE-2025-11001/11002によりリモートから任意コード実行の恐れ 📂 シンボリックリンク処理の欠陥が原因 💥 影響範囲:最新リリース

    @wow24369

    13 Oct 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 壓縮工具 7-Zip 存在高風險漏洞 (CVE-2025-11001, CVE-2025-11002)。 風險:解壓縮惡意 ZIP 檔,可能導致遠端程式碼執行。 主因:7-Zip 缺乏自動更新機制,大量用戶仍在使用舊的、有漏洞的版本。 解法:請立即手動前往

    @Easy2Tips

    12 Oct 2025

    199 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. 🚨 Dos vulnerabilidades críticas en 7-Zip ⚠️ CVE-2025-11001 ⚠️ CVE-2025-11002 https://t.co/ab04trVtBO https://t.co/MxO228J5V5

    @elhackernet

    12 Oct 2025

    25978 Impressions

    81 Retweets

    372 Likes

    95 Bookmarks

    4 Replies

    7 Quotes

  21. 7-Zip의 ZIP 파일 파싱 취약점(ZDI-25-949)이 공개 디렉토리 트래버설로 원격 코드 실행 가능 CVE-2025-11001 (CVSS 7.0) 25.00 버전으로 업데이트 필요https://t.co/ZUHI6MaThP

    @PiesP

    12 Oct 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🛡️ Abrir el archivo equivocado en 7-Zip puede comprometer tu red Dos vulnerabilidades graves (CVE-2025-11001 y CVE-2025-11002) afectan a todas las versiones de 7-Zip anteriores a la 25.00. Permiten a un atacante ejecutar código malicioso al manipular cómo se procesan en

    @CycuraMX

    11 Oct 2025

    2252 Impressions

    14 Retweets

    34 Likes

    16 Bookmarks

    1 Reply

    0 Quotes

  23. https://t.co/SfNAVEee2o 🛑 Two high-risk vulnerabilities in 7-Zip (CVE-2025-11001, 11002) allow arbitrary code execution via crafted ZIP files. 📂 The flaws stem from symlink handling, letting archives escape extraction folders and write files anywhere on the system — eve

    @GameGPU_com

    11 Oct 2025

    99 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Flaws (CVE-2025-11001 & CVE-2025-11002) in 7-Zip allow attackers to gain RCE by exploiting directory traversal via malicious ZIP files. Update immediately to v25.00. #7Zip #RCE #Cybersecurity #ZipFlaw #ZDI https://t.co/2ovXgisOfC

    @the_yellow_fall

    11 Oct 2025

    262 Impressions

    4 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  25. 🚨CVE-2025-11002 and CVE-2025-11001: 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability CVSS: 7.0 / 7.0 Advisory: https://t.co/RYUZ5EoBlH and https://t.co/shEWNSXUQv Fixed in 7-Zip 25.00

    @DarkWebInformer

    10 Oct 2025

    6158 Impressions

    9 Retweets

    49 Likes

    16 Bookmarks

    2 Replies

    1 Quote

  26. ⚠️ Per chi fosse interessato: vulnerabilità ( CVE-2025-11001 e CVE-2025-11002) in #7Zip consentono agli aggressori di eseguire codice arbitrario da remoto. Aggiornamento alla versione 25.00 disponibile. 🔗 https://t.co/k2vcZGHfNp https://t.co/fLvlveEUHd

    @sonoclaudio

    10 Oct 2025

    307 Impressions

    0 Retweets

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  27. 7-Zipで深刻な任意コード実行の脆弱性が修正。CVE-2025-11001とCVE-2025-11002はCVSSスコア7.0。シンボリックリンクリンクの取扱いに起因。バージョン25.00で修正。GMO Flatt SecurityのRyota Shiga氏がTakumiで発見。 https://t.co/O4W

    @__kokumoto

    10 Oct 2025

    1183 Impressions

    6 Retweets

    11 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 7-Zip Vulnerabilities Allow Remote Code Execution Two critical flaws (CVE-2025-11001 & CVE-2025-11002). ✅ By exploiting symbolic links in archives, attackers can execute arbitrary code - patch immediately 🎯 🔗 https://t.co/dPuEkTc7tz #CyberSecurity #News

    @MME_IT

    10 Oct 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability (CVE-2025-11001) #7Zip #CVE202511001 #CyberSecurity #RemoteCodeExecutionVulnerability https://t.co/S4N6sCtTr6

    @SystemTek_UK

    9 Oct 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.