logo

7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now

ID: 6138ce88-ec14-53c4-85d8-d490435fb918

STIX ID: report--6138ce88-ec14-53c4-85d8-d490435fb918

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-01-21

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical vulnerability (CVE-2025-0411) in 7-Zip allowed attackers to bypass Windows Mark-of-the-Web protections for files extracted from nested archives, potentially enabling execution of arbitrary code; the issue was patched in 7-Zip 24.09 on 2024-11-30, but many users remain at risk because 7-Zip lacks auto-update. The report also highlights similar MotW bypass vulnerabilities that have been weaponized to deliver malware, underscoring the need for prompt patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.