
🚨 HIGH - 7-Zip Compound Document handler null pointer dereference DoS (CVE-2025-53817) 7-Zip contains a null pointer dereference in its Compound document extraction handler triggered while parsing crafted Compound Document files. The underlying flaw is a null pointer dereference due to improper validation of internal pointers/structures during extraction. An attacker can exploit this by convincing a user or automated scanning pipeline to open or extract a malicious Compound Document archive/file, requiring no special privileges beyond the ability to supply the file. Successful exploitation causes a reliable denial of service via application crash, disrupting desktop use or backend file-processing workflows. 👉 Affected: 7-Zip < 25.0.0 | Upgrade to 25.0.0
Post summary
7-Zip vulnerability CVE-2025-53817 causes a null pointer dereference leading to denial of service; upgrading to 25.0.0 patches the flaw.
