logo

Analysis of 7-Zip vulnerabilities: CVE-2025-11001 and CVE-2025-11002

ID: 8be2f432-f622-51f7-be9f-0c4f8b09bb45

STIX ID: report--8be2f432-f622-51f7-be9f-0c4f8b09bb45

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2025-12-12

Date Updated: 2026-05-01

...
...

This advisory details two 7‑Zip vulnerabilities (CVE-2025-11001 and CVE-2025-11002) where improper handling of Linux symbolic links on Windows leads to path-traversal during extraction of crafted ZIP files, enabling attackers to write files (including potentially malicious executables) to locations such as the Windows Startup folder and achieve code execution as a service account; both issues are rated CVSS 7.0 and resolved in 7‑Zip 25.00, and the report recommends least-privilege, application control, and ThreatLocker-specific mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.