CVE-2025-0411Patch(7-zip / 7-zip)

MEDIUMCVSS 7.0 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch 7-zip 7-zip systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-02-27. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-693

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7-zip
  • active_iq_unified_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-01-30); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
7-zipactive_iq_unified_manager

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-30: 1Mentions · 2026-02-12: 1Mentions · 2026-04-24: 1Mentions · 2026-07-21: 1Active Exploitation · 2026-02-12: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-07-21: 1Technical Details · 2026-02-12: 1Technical Details · 2026-07-21: 101-3002-1204-2407-21
Signal classification3 categories
Patch
250.0%
Active Exploitation
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-301
Patch1
2026-02-121
Active Exploitation1
2026-04-241
General1
2026-07-211
Patch1
Full discourse4 posts
  • Vedant Kalore@VedantKalore
    Patch

    Meanwhile our government is screwed, you better don't get. There is a serious Vulnerability: CVE-2025-0411 in 7-Zip which allows for remote code execution when unzipping XZ archives which are made in malicious ways to execute malicious code or website. Kindly update to 7-Zip version 26.02 to be safe. Website: https://www.7-zip.org/

    Post summary

    The post announces CVE‑2025‑0411 in 7‑Zip, highlights its RCE risk via malicious XZ archives, and urges users to update to version 26.02.

    00030159
    1.1K followersView on X
  • Klungs@kweelungsin
    General

    @ChShersh Nevermind, 7zip got CVE last year. Trust is gon. https://nvd.nist.gov/vuln/detail/CVE-2025-0411

    Post summary

    The tweet merely points to a CVE for 7zip and links to its NVD page, offering no further technical or actionable information.

    0000081
    19 followersView on X
  • [labunix@らぼゆにっくす:~]$@labunix
    Active Exploitation

    https://www.trendmicro.com/ja_jp/research/25/b/cve-2025-0411-ukrainian-organizations-targeted.html

    Post summary

    Trend Micro reports that CVE‑2025‑0411 is actively exploited against Ukrainian organizations, with vendor patches available and technical details disclosed.

    0000067
    5.0K followersView on X
  • Beardyface@Beardyface4
    Patch

    @rich_hedge_fund Patched in version 7.13, if you're talking out of date software, then so does 7zip CVE-2025-0411 (versions prior to 24.09). Use whichever you like, just keep your software up to date.

    Post summary

    The message notes that CVE‑2025‑0411 has been patched in software version 7.13 and older 7zip versions before 24.09, urging users to keep their software updated.

    00000212
    640 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
App7-zip7-zip---
Appnetappactive_iq_unified_manager-windows-

Explore more