Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

7-Zip Vulnerabilities Allows Remote Attackers to Execute Arbitrary Code

Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip , which could allow remote attackers to execute arbitrary code.

Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip , which could allow remote attackers to execute arbitrary code.

Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.

The core of both vulnerabilities lies within the way 7-Zip handles symbolic links embedded in ZIP archives. According to the advisory, a threat actor can create a malicious ZIP file containing crafted data that exploits this weakness.

When a user with a vulnerable version of 7-Zip attempts to decompress the archive, the flawed process can be manipulated to perform a directory traversal.

This allows the extraction process to write files outside of the intended destination folder, potentially placing malicious payloads in sensitive system locations.

While the attack is initiated remotely through the delivery of the malicious file, exploitation requires user interaction, as the victim must choose to open the archive. The specific attack vectors may vary depending on how 7-Zip is implemented within different environments.

Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.
Hazel Caldwell · Thehackingpost

Both CVE-2025-11001 and CVE-2025-11002 have been assigned a CVSS 3.0 score of 7.0, classifying them as high-severity threats.

A successful exploit could allow an attacker to execute arbitrary code on the affected system with the privileges of the service account or user running the 7-Zip application.

This could lead to a full system compromise, data theft, or the deployment of further malware such as ransomware.

The high complexity of the attack and the requirement for user interaction prevent the vulnerabilities from receiving a critical rating, but the potential impact on confidentiality, integrity, and availability remains significant given the widespread use of the 7-Zip utility.

Advertisement

CVE IDAffected ProductVulnerabilityCVSS 3.0 ScoreCVE-2025-110027-Zip (versions before 25.00)Arbitrary Code Execution via Symbolic Link Handling7.0 (High)CVE-2025-110017-Zip (versions before 25.00)Arbitrary Code Execution via Symbolic Link Handling7.0 (High) The developer of 7-Zip has released version 25.00, which rectifies these security flaws. All users are strongly advised to update their installations immediately to protect against potential exploitation.

The vulnerabilities were initially reported to the vendor on May 2, 2025, following a responsible disclosure timeline.

A coordinated public advisory was subsequently released on October 7, 2025, to inform the public of the risks and the available patch. These vulnerabilities were uncovered by security researcher Ryota Shiga of GMO Flatt Security Inc., working with takumi-san.ai.

Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories