https://seclists.org/oss-sec/2025/q3/91: CVE-2025-55188: 7-Zip: Arbitrary file write on extraction, may lead to code execution
Published Aug 11, 2025
·Updated
Affected Software
1 affected component
7-Zip 7-Zip
Frequently Asked Questions
1
What is the severity of CVE-2025-55188?
CVE-2025-55188 has a high severity rating due to the potential for arbitrary file write and possible code execution.
2
How do I fix CVE-2025-55188?
To fix CVE-2025-55188, update to the latest version of 7-Zip where the vulnerability has been patched.
3
What systems are affected by CVE-2025-55188?
CVE-2025-55188 affects all versions of 7-Zip prior to the patched release on August 11, 2025.
4
What kind of attack does CVE-2025-55188 enable?
CVE-2025-55188 enables arbitrary file write attacks during extraction, which may lead to remote code execution.
5
Is user data at risk with CVE-2025-55188?
Yes, user data may be at risk if an attacker exploits CVE-2025-55188 to execute malicious code.