CVE-2025-0411: 7-Zip Mark of the Web Bypass Vulnerability
7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
Other sources
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigations per vendor instructions for the 7-Zip Mark-of-the-Web bypass vulnerability (ZDI-CAN-25456), or discontinue use of 7-Zip if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0411?
CVE-2025-0411 is classified as a moderate severity vulnerability.
How do I fix CVE-2025-0411?
To fix CVE-2025-0411, update your 7-Zip installation to the latest version provided by the vendor.
What systems are affected by CVE-2025-0411?
CVE-2025-0411 affects installations of 7-Zip that are configured with the Mark-of-the-Web protection mechanism.
Can CVE-2025-0411 be exploited without user interaction?
No, exploiting CVE-2025-0411 requires user interaction, such as visiting a malicious webpage.
What type of vulnerability is CVE-2025-0411?
CVE-2025-0411 is a Mark-of-the-Web bypass vulnerability in the 7-Zip software.