CVE-2025-0411

CVSS 3.1 Score 7 of 10 (high)

Details

Published Jan 25, 2025
Updated: Feb 12, 2025
CWE ID 693

Summary

CVE-2025-0411 is a vulnerability affecting 7-Zip's Mark-of-the-Web (MotW) protection mechanism. This issue allows remote attackers to bypass MotW on affected installations, leading to potential code execution. The flaw lies in the archived files handling process; when extracting from a maliciously crafted archive, MotW is not propagated to extracted files. User interaction is necessary for exploitation, either through visiting a malicious webpage or opening a malicious file. This vulnerability, identified as ZDI-CAN-25456, can result in arbitrary code execution in the context of the current user.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share