CVE-2025-0411β€”7-Zip Mark of the Web Bypass Vulnerability

PUBLISHEDvulnerability record
2025-02-06 Β· last modified June 21, 2025

Metadata

CVE ID:
CVE-2025-0411
Project:
7-Zip
Product:
7-Zip
Date Added:
2025-02-06
Due Date:
2025-02-27
Last Updated:
June 21, 2025

Vulnerability Name

7-Zip Mark of the Web Bypass Vulnerability

Description

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

Related News Articles

Related Weaknesses