ZDI-25-045: 7-Zip Mark-of-the-Web Bypass Vulnerability
This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.
Other sources
This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2025-0411.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-25-045 - Configuration
When extracting from archives that bear Mark-of-the-Web, ensure 7-Zip propagates the Mark-of-the-Web to the extracted files so the Mark-of-the-Web protection mechanism is not bypassed (issue noted: MoTW is not propagated during extraction of crafted archives).
7-Zip Mark-of-the-Web (MoTW) propagation during extraction = Propagate MoTW to extracted files (do not omit) - Compensating control
Avoid opening or extracting malicious archives/files, since user interaction is required (e.g., do not open files or visit pages hosting crafted archives intended to bypass Mark-of-the-Web).
Event History
Frequently Asked Questions
What is the severity of ZDI-25-045?
The severity of ZDI-25-045 is considered critical due to the potential for remote code execution.
How do I fix ZDI-25-045?
To fix ZDI-25-045, update your 7-Zip installation to the latest version provided by the vendor.
What does ZDI-25-045 exploit?
ZDI-25-045 exploits a flaw that allows remote attackers to bypass the Mark-of-the-Web protection mechanism.
Is user interaction required to exploit ZDI-25-045?
Yes, user interaction is required for ZDI-25-045, as the target must visit a malicious page or open a malicious file.
What software is affected by ZDI-25-045?
ZDI-25-045 affects installations of the 7-Zip file archiver software.