CVE-2025-0411 is a Mark-of-the-Web bypass vulnerability in 7-Zip that allows attackers to deliver malware without Windows security warnings. Despite being listed in CISA KEV, this is a client-side vulnerability requiring user interaction (opening a malicious archive) and does not affect internet-facing servers.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2025-01-25
Added to CISA KEV: 2025-02-06 12 DAYS BETWEEN CVE AND KEV
CVE-2025-0411 is a security vulnerability that was identified in 7-Zip and disclosed to its creator, Igor Pavlov, leading to a patch in version 24.09 on November 30, 2024 [1].
| Feature | Description |
|---|---|
| Vulnerability Type | Mark-of-the-Web (MotW) bypass |
| Affected Product | 7-Zip (versions prior to 24.09) [1] |
| Exploitation | Active in the wild (targeted attacks) [1] |
| Requirement | User interaction (e.g., opening a malicious file) [4] |
| Impact | Bypass of security checks, potential arbitrary code execution [3] |
| Status | Patched in version 24.09 [1] |
The vulnerability was actively exploited by Russian cybercrime groups through spear-phishing campaigns, using homoglyph attacks to spoof ... The vulnerability, CVE-2025-0411, was disclosed to 7-Zip creator Igor Pavlov, leading to the release of a patch in version 24.09 on November 30, 2024. CVE-2025…
The vulnerability, CVE-2025-0411, was disclosed to 7-Zip creator Igor Pavlov, leading to the release of a patch in version 24.09 on 30/11/2024. CVE-2025-0411 allows the bypassing of Windows Mark-of-the-Web protections by double archiving files, thus preventing necessary security checks and allowing…
Jan 20, 2025 at 11:53 PM Threat Intelligence Report CVE-2025-0411 is a critical security vulnerability in 7-Zip, with a CVSS score of 7.0, that allows attackers to execute arbitrary code by bypassing the "Mark-of-the-Web" security feature in Windows. ... CVEs. CVE-2025-0411. Proof of exploitProof of…
CVE-2025-0411 Detail.This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…