CVE-2025-11001 is a directory traversal vulnerability in 7-Zip's handling of ZIP files, affecting 7-Zip on Windows. This flaw allows remote attackers to achieve arbitrary code execution by crafting a malicious ZIP file that causes the application to traverse to unintended directories. Rated 7.8 HIGH on CVSS, exploitation requires user interaction and can lead to code execution in the context of a service account. While there is no public exploit code available, the vulnerability has garnered community discussion and media coverage, with reports of it being exploited in attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24.09CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:24.09:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.