CVE-2025-11001

HIGH EXPLOITED

7-Zip - Remote Code Execution

Title source: llm

Description

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.

Exploits (7)

github WORKING POC 149 stars
by pacbypass · pythonlocal
https://github.com/pacbypass/CVE-2025-11001
nomisec WORKING POC 8 stars
by mbanyamer · local
https://github.com/mbanyamer/CVE-2025-11001---7-Zip
nomisec WORKING POC
by I3r1h0n · client-side
https://github.com/I3r1h0n/7Ziprowler
nomisec WORKING POC
by ranasen-rat · local
https://github.com/ranasen-rat/CVE-2025-11001
nomisec WORKING POC
by lastvocher · local
https://github.com/lastvocher/7zip-CVE-2025-11001
vulncheck_xdb SCANNER
local
https://github.com/shalevo13/Se7enSlip

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-01-20
CWE
CWE-22
Status published
Products (1)
7-zip/7-zip 24.09
Published Nov 19, 2025
Tracked Since Feb 18, 2026