https://seclists.org/oss-sec/2025/q4/25: CVE-2025-55188: 7-Zip: Arbitrary file write on extraction, may lead to code execution
Published Oct 12, 2025
·Updated
Affected Software
1 affected component
7-Zip 7-Zip>=25.00
Frequently Asked Questions
1
What is the severity of CVE-2025-55188?
CVE-2025-55188 has been classified as a high severity vulnerability due to its potential to allow arbitrary file writes, which may lead to code execution.
2
How do I fix CVE-2025-55188?
To mitigate CVE-2025-55188, users should update to the latest version of 7-Zip where this vulnerability has been patched.
3
What type of vulnerability is CVE-2025-55188?
CVE-2025-55188 is classified as an arbitrary file write vulnerability during the extraction process in 7-Zip.
4
Which versions of 7-Zip are affected by CVE-2025-55188?
CVE-2025-55188 affects multiple versions of 7-Zip prior to the update that addresses this vulnerability.
5
Can CVE-2025-55188 lead to remote code execution?
Yes, CVE-2025-55188 can potentially allow an attacker to execute arbitrary code on the affected system due to the arbitrary file write capability.