logo

PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution

ID: f45c9ffa-e75b-5832-b543-0673753ecdf6

STIX ID: report--f45c9ffa-e75b-5832-b543-0673753ecdf6

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-10-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A proof-of-concept exploit for two 7-Zip flaws (CVE-2025-11001 and CVE-2025-11002) demonstrates how improper symlink handling during ZIP extraction on Windows can be abused to perform path traversal and write arbitrary files (potentially leading to code execution). The issues affect 7-Zip versions 21.02 through 24.09, have CVSS v3.0 scores of 7.0, and are fixed in 25.00; users are advised to update immediately, disable symlink support where possible, and scan archives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.