HomeSecurityHackers exploit 7-Zip RCE vulnerability

Hackers exploit 7-Zip's RCE vulnerability

A recent vulnerability affecting 7-Zip is being actively exploited, according to a statement issued by NHS England Digital on Tuesday.

7-Zip vulnerability

The vulnerability in question is CVE-2025-11001 (CVSS score: 7.0), which allows remote attackers to execute arbitrary code. The issue has been addressed in 7-Zip version 25.00, released in July 2025.

See also: WordPress: Serious vulnerability in the W3 Total Cache plugin

“ This vulnerability exists in the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to jump to unwanted directories ,” Trend Micro’s Zero Day Initiative (ZDI) said in an advisory released last month. “ An attacker could exploit this vulnerability to execute code under a service account .”

Hackers exploit 7-Zip's RCE vulnerability

7-Zip: Vulnerability Fix

It is worth noting that 7-Zip version 25.00 also fixes another security flaw, CVE-2025-11002 (CVSS score: 7.0), which allows remote code execution via improper handling of symbolic links within ZIP files. Both vulnerabilities were introduced in version 21.02.

See also: Operation WrtHug: Exploiting vulnerabilities to infect EoL ASUS routers

“has been observed Active exploitation of CVE-2025-11001,” NHS England Digital said. However, details on how it is being used, by whom, and in what context are currently unavailable.

Given that there are proofs of exploit (PoC), it is essential that 7-Zip users proceed quickly to apply the necessary fixes, if they have not already done so.

See also: Fortinet's silent update exploits serious flaw in FortiWeb

Hackers exploit 7-Zip's RCE vulnerability

“This flaw can only be exploited from within the context of an elevated user/service account or a machine with developer mode enabled,” said security researcher Dominik (aka pacbypass), who released the PoC. “This vulnerability can only be exploited on Windows,” he concluded.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS