Two high-severity vulnerabilities have been discovered in the popular file archiver software, 7-Zip. The vulnerabilities could allow remote attackers to execute arbitrary code. The vulnerabilities, identified as CVE-2025-11001 and CVE-2025-11002, affect all versions of the software prior to the latest release and require immediate patching.

The crux of both vulnerabilities lies in the way 7-Zip handles symbolic links embedded in ZIP files. According to the announcement, a malicious actor could create a file ZIP containing crafted data that exploits this weakness.
See also: Vulnerability in Microsoft Events platform exposes personal data
When a user with a vulnerable version of 7-Zip attempts to decompress the archive, the flawed process can be manipulated to perform directory traversal. This allows the extraction process to write files outside of the intended destination folder, potentially placing malicious payloads in sensitive locations on the system.
While the attack is initiated remotely via the delivery of the malicious file, the exploit requires user interaction, as the victim must choose to open the file. The specific attack vectors may vary depending on how 7-Zip is implemented in different environments.

7-Zip: Serious vulnerabilities – Greater risk
Both CVE-2025-11001 and CVE-2025-11002 have received a CVSS score of 7.0/10, which classifies them as high severity threats. A successful exploit could allow an attacker to execute arbitrary code on the affected system with the privileges of the service account or user running the 7-Zip application. This could lead to a complete system compromise, data theft , or the deployment of further malware such as ransomware.
See also: PoC Exploit for Code Execution Vulnerability in Nothing Phone
The high complexity of the attack and the requirement for user interaction prevent the vulnerabilities from receiving a critical rating, but the potential impact on confidentiality, integrity, and availability remains significant given the widespread use of the 7-Zip tool.
The developer of 7-Zip has released version 25.00, which fixes these security vulnerabilities. All users are strongly advised to update their installations immediately to protect themselves from potential exploitation.
See also: GitLab Security Update – Fixing Multiple Vulnerabilities

The vulnerabilities were reported to the vendor on May 2, 2025, following a responsible disclosure schedule. A coordinated public notice was released on October 7, 2025, to inform the public of the risks and the available fix. These vulnerabilities were discovered by security researcher Ryota Shiga of GMO Flatt Security Inc., in collaboration with takumi-san.ai.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
