CVE-2025-0411

7-Zip Mark-of-the-Web Bypass Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
January 13, 2025
Published Date
January 25, 2025
Last Updated
February 07, 2025
Vendor
7-Zip
Product
7-Zip
Description
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CVSS Scores

CVSS v3.0

7.0 - HIGH

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2025-02-06 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2025-03-13 19:53:22 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-02-06 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

dpextreme/7-Zip-CVE-2025-0411-POC

Type: github • Created: 2025-03-13 19:53:22 UTC • Stars: 1

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.

cesarbtakeda/7-Zip-CVE-2025-0411-POC

Type: github • Created: 2025-02-23 02:55:44 UTC • Stars: 1

ishwardeepp/CVE-2025-0411-MoTW-PoC

Type: github • Created: 2025-02-19 04:47:59 UTC • Stars: 0

iSee857/CVE-2025-0411-PoC

Type: github • Created: 2025-01-27 07:32:09 UTC • Stars: 1

7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)

dhmosfunk/7-Zip-CVE-2025-0411-POC

Type: github • Created: 2025-01-22 14:40:34 UTC • Stars: 129

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.