ZDI-CAN-25456: ZDI-25-045: 7-Zip Mark-of-the-Web Bypass Vulnerability
This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.
Other sources
This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2025-0411.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
7-Zipto a version that resolves this vulnerability.Patch ZDI-25-045 - Compensating control
When extracting files from crafted archives, treat Mark-of-the-Web bypass behavior as untrusted: avoid extracting archives from untrusted sources and ensure extracted files are handled in a way that does not grant them trust (since 7-Zip does not propagate Mark-of-the-Web to extracted files).
- Operational
If a crafted archive was opened or extracted, review and remediate any files that may have been affected; assume arbitrary code could have executed in the context of the current user.
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25456?
The severity of ZDI-CAN-25456 is significant, as it allows remote attackers to bypass important security mechanisms.
How do I fix ZDI-CAN-25456?
To fix ZDI-CAN-25456, ensure you have the latest version of 7-Zip installed, which includes patches for known vulnerabilities.
What types of attacks can occur due to ZDI-CAN-25456?
ZDI-CAN-25456 can lead to attacks where a user is tricked into visiting a malicious page or opening a harmful file.
Is user interaction required to exploit ZDI-CAN-25456?
Yes, user interaction is required to exploit ZDI-CAN-25456, as the target must open a malicious file or visit a malicious webpage.
Which versions of 7-Zip are affected by ZDI-CAN-25456?
ZDI-CAN-25456 affects all installations of 7-Zip that have not been updated with the latest security patches.