← Back to CVE List
Vulnerability Intelligence Report
7-Zip Mark-of-the-Web Bypass Vulnerability

CVE-2025-0411

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.0
HIGH
Exploitability:1.1
Impact Score:5.9
EPSS Probability:67.07%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-693 ↗CWE-693: Protection Mechanism Failure

Affected Products & Versions

Vendor Product Affected Versions
7-Zip 7-Zip 24.08 (x64) (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
67.071%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityZero Day Initiative · Bug Bounty Provider · Japan
Reserved2025-01-13T03:13:25
Published2025-01-25T04:28:24
Patch Date2025-01-20
Last Updated2026-02-26T19:08:56

LINK COPIED TO CLIPBOARD