CVE-2025-0411 is a critical Mark-of-the-Web bypass vulnerability in 7-Zip, affecting 7-Zip itself and products like NetApp Active IQ Unified Manager that incorporate it. This flaw allows attackers to craft malicious archives that, upon extraction, do not propagate the Mark-of-the-Web to extracted files, enabling arbitrary code execution in the user's context. With a CVSS score of 7.0 (High), the vulnerability requires user interaction to open a malicious file or visit a malicious page, but its impact is severe, leading to high confidentiality, integrity, and availability compromise. The EPSS score of 0.50945 indicates a high likelihood of exploitation. This vulnerability is actively exploited in the wild, particularly in attacks against Ukraine, and is listed in the KEV catalog. While no public exploit code is available on platforms like Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, highlighting its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* | ||
< 24.09CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.