CVE-2025-11001Patch(7-zip / 7-zip)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch 7-zip 7-zip systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7-zip
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-04)
  • 5 total mentions across 4 days

Affected systems

Products
7-zipwindows

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-30: 1Mentions · 2026-05-12: 1Mentions · 2026-07-26: 1Mentions · 2026-08-04: 2PoC Mentioned / Linked · 2026-07-26: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-01-30: 101-3005-1207-2608-04
Signal classification3 categories
Patch
360.0%
Exploit
120.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-301
Patch1
2026-05-121
Patch1
2026-07-261
Exploit1
2026-08-042
General1Patch1
Full discourse5 posts
  • CVE Brief@DailyCVEBrief
    Patch

    LOOK BACK — 7-Zip fixed CVE-2025-11001 on July 5, 2025. The advisory came October 7. The NVD record came November 19. By the time scanners flagged it, the patch was four months old. Then a national advisory called it actively exploited, and withdrew that two days later. https://t.co/xDFsIOP2FA

    Post summary

    The post highlights that 7‑Zip had patched CVE‑2025‑11001 months before scanners flagged, and notes that a national advisory wrongly claimed the vulnerability was being actively exploited but later retracted the claim.

    1000051
    25 followersView on X
  • Zymeralabs@Zymeralabs
    Exploit

    7-Zip tiene un fallo que permite ejecutar código en tu sistema. 🗜️ CVE-2025-11001: abres un .zip malicioso, el atacante entra. Sin más pasos. Exploit público disponible. NHS England ya alertó. Sectores salud y finanzas afectados. Solución: actualiza a 7-Zip v25.00 ahora mismo. Es gratis y está disponible.

    Post summary

    7‑Zip CVE‑2025‑11001 allows arbitrary code execution via malicious ZIP files; a public exploit is available, NHS England has issued a warning, and the fix is to update to v25.00.

    1000038
    20 followersView on X
  • CVE Brief@DailyCVEBrief
    General

    Full Look Back: what the bug actually was (not the dot-dot-slash everyone wrote up), why it never reached KEV, and how a retracted exploitation claim kept circulating for weeks: https://cvebrief.com/cve/CVE-2025-11001/ https://t.co/CCEDalry2c

    Post summary

    The tweet references an article that clarifies what CVE-2025-11001 actually entails, debunks a previously retracted exploitation claim, and explains why it never reached the KEV list.

    0000036
    25 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Debian 11 releases p7zip and p7zip-rar security updates, replacing codebase with 7-Zip v25 to fix 10 CVEs including CVE-2022-47069 and CVE-2025-11001. https://threatcluster.io/cluster/debian-updates-address-multiple-p7zip-vulnerabilities-a59c5b06

    Post summary

    Debian 11 has issued updates for p7zip and p7zip‑rar, fixing ten CVEs by upgrading to 7‑Zip v25.

    00000691
    244 followersView on X
  • Grok@grok
    Patch

    @zeark969 @TAIKI_PCyoutube 7-Zipには2025年に脆弱性(例: CVE-2025-11001)が発見され、細工されたファイルでRCEのリスクがあった。ただし、最新版25.01以降で修正済み。公式サイトから更新し、信頼できないアーカイブを開かないよう注意を。安全に使えます。

    Post summary

    7‑Zip の CVE‑2025‑11001 は RCE リスクを含むが、バージョン 25.01 以降で修正済み。公式サイトからアップデートし、信頼できないアーカイブを避けることで安全に利用できる。

    00000624
    8.1M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
App7-zip7-zip24.09--
OSmicrosoftwindows--x64

Explore more