🟢 CVE-2025-0411

CVE-2025-0411 is a Mark-of-the-Web bypass vulnerability in 7-Zip that allows attackers to deliver malware without Windows security warnings. Despite being listed in CISA KEV, this is a client-side vulnerability requiring user interaction (opening a malicious archive) and does not affect internet-facing servers.

← Back to Overview
LOW_RISK
Risk Level
7.0
CVSS Score
LOCAL
Attack Vector
Execution
ATT&CK Tactic
T1204 — User Execution
ATT&CK Technique
VERY_LOW
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: USER_INTERACTION

CVE Published: 2025-01-25

Added to CISA KEV: 2025-02-06 12 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2025-0411 is a security vulnerability that was identified in 7-Zip and disclosed to its creator, Igor Pavlov, leading to a patch in version 24.09 on November 30, 2024 [1].

Key Details
FeatureDescription
Vulnerability TypeMark-of-the-Web (MotW) bypass
Affected Product7-Zip (versions prior to 24.09) [1]
ExploitationActive in the wild (targeted attacks) [1]
RequirementUser interaction (e.g., opening a malicious file) [4]
ImpactBypass of security checks, potential arbitrary code execution [3]
StatusPatched in version 24.09 [1]
Analysis
  • Active Exploitation and Threat Actors: This vulnerability was actively exploited in the wild by Russian cybercrime groups to target Ukrainian organizations [1].
  • Attack Method: The attack involves bypassing Windows "Mark-of-the-Web" (MotW) protections by using a double-archiving technique (e.g., a nested archive structure like `poc.outer.zip/poc.inner.zip/poc.bat`) [2]. This prevents necessary security checks from triggering, allowing the execution of malicious content [1]. Attackers also utilized homoglyph attacks to spoof files in spear-phishing campaigns [1].
  • Exploitation Requirements: Exploitation requires user interaction, specifically the target opening a malicious file or visiting a malicious page [4].
  • Proof-of-Concept: Working proof-of-concept (PoC) exploits utilizing the nested archive structure have been documented by security researchers [2].
  • Impact: Successful exploitation allows attackers to bypass security protections and potentially execute arbitrary code in the context of the current user [3].
*Note: Some online sources may incorrectly associate CVE-2025-0411 with other products (such as Microsoft Exchange); however, the primary research from security vendors identifies this specific CVE as a 7-Zip vulnerability [1].*

Sources

  1. CVE-2025-0411: Ukrainian Organizations Targeted in Zero ...

    The vulnerability was actively exploited by Russian cybercrime groups through spear-phishing campaigns, using homoglyph attacks to spoof ... The vulnerability, CVE-2025-0411, was disclosed to 7-Zip creator Igor Pavlov, leading to the release of a patch in version 24.09 on November 30, 2024. CVE-2025…

  2. CVE-2025-0411: Ukrainian Organisations Targeted... | Trend Micro (UK)

    The vulnerability, CVE-2025-0411, was disclosed to 7-Zip creator Igor Pavlov, leading to the release of a patch in version 24.09 on 30/11/2024. CVE-2025-0411 allows the bypassing of Windows Mark-of-the-Web protections by double archiving files, thus preventing necessary security checks and allowing…

  3. CVE-2025-0411 - Exploits & Severity - Feedly

    Jan 20, 2025 at 11:53 PM Threat Intelligence Report CVE-2025-0411 is a critical security vulnerability in 7-Zip, with a CVSS score of 7.0, that allows attackers to execute arbitrary code by bypassing the "Mark-of-the-Web" security feature in Windows. ... CVEs. CVE-2025-0411. Proof of exploitProof of…

  4. NVD - cve-2025-0411

    CVE-2025-0411 Detail.This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…