Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-0411

89
FAUCET Score

CVE-2025-0411 is a critical Mark-of-the-Web bypass vulnerability in 7-Zip, affecting 7-Zip itself and products like NetApp Active IQ Unified Manager that incorporate it. This flaw allows attackers to craft malicious archives that, upon extraction, do not propagate the Mark-of-the-Web to extracted files, enabling arbitrary code execution in the user's context. With a CVSS score of 7.0 (High), the vulnerability requires user interaction to open a malicious file or visit a malicious page, but its impact is severe, leading to high confidentiality, integrity, and availability compromise. The EPSS score of 0.50945 indicates a high likelihood of exploitation. This vulnerability is actively exploited in the wild, particularly in attacks against Ukraine, and is listed in the KEV catalog. While no public exploit code is available on platforms like Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, highlighting its importance.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
< 24.09CPE matchmatch criteria
cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.0HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
67.07%
Probability of exploitation in next 30 days
EPSS Percentile
99.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Feb 6, 2025
This CVE's current EPSS score of 0.6707 is in the 100th percentile among its peer group of 386 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

debianpatch availablevia osv
Product: 7zipFixed in: 24.09+dfsg-1
debianpatch availablevia osv
Product: p7zipFixed in: 16.02+transitional.1
debianvendor investigatingvia osv
Product: 7zip
debianvendor investigatingvia osv
Product: p7zip

Vendor Advisories (1)

debianCVE-2025-0411

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the

Jan 25, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
security.netapp.com / advisory/ntap-20250207-0005
Third Party Advisory
vicarius.io / vsociety/posts/cve-2025-0411-7-zip-mitigation-vulnerability
Mitigation
vicarius.io / vsociety/posts/cve-2025-0411-detection-7-zip-vulnerability
Mitigation
openwall.com / lists/oss-security/2025/01/24/6
Mailing List
zerodayinitiative.com / advisories/ZDI-25-045
Third Party AdvisoryVDB Entry